Description
Mozilla Firefox before 1.5.0.7 and Thunderbird before 1.5.0.7 makes it easy for users to accept self-signed certificates for the auto-update mechanism, which might allow remote user-assisted attackers to use DNS spoofing to trick users into visiting a malicious site and accepting a malicious certificate for the Mozilla update site, which can then be used to install arbitrary code on the next update.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2006-4555 | Mozilla Firefox before 1.5.0.7 and Thunderbird before 1.5.0.7 makes it easy for users to accept self-signed certificates for the auto-update mechanism, which might allow remote user-assisted attackers to use DNS spoofing to trick users into visiting a malicious site and accepting a malicious certificate for the Mozilla update site, which can then be used to install arbitrary code on the next update. |
Ubuntu USN |
USN-350-1 | Thunderbird vulnerabilities |
Ubuntu USN |
USN-351-1 | firefox vulnerabilities |
Ubuntu USN |
USN-352-1 | Thunderbird vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T19:14:47.523Z
Reserved: 2006-09-06T00:00:00.000Z
Link: CVE-2006-4567
No data.
Status : Modified
Published: 2006-09-15T18:07:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2006-4567
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN