CVE-2006-4253

Severity

76%

Complexity

49%

Confidentiality

165%

Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency failure that causes structures to be freed incorrectly, as demonstrated by (1) ffoxdie and (2) ffoxdie3. NOTE: it has been reported that Netscape 8.1 and K-Meleon 1.0.1 are also affected by ffoxdie. Mozilla confirmed to CVE that ffoxdie and ffoxdie3 trigger the same underlying vulnerability. NOTE: it was later reported that Firefox 2.0 RC2 and 1.5.0.7 are also affected.

Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency failure that causes structures to be freed incorrectly, as demonstrated by (1) ffoxdie and (2) ffoxdie3. NOTE: it has been reported that Netscape 8.1 and K-Meleon 1.0.1 are also affected by ffoxdie. Mozilla confirmed to CVE that ffoxdie and ffoxdie3 trigger the same underlying vulnerability. NOTE: it was later reported that Firefox 2.0 RC2 and 1.5.0.7 are also affected.

CVSS 2.0 Base Score 7.6. CVSS Attack Vector: network. CVSS Attack Complexity: high. CVSS Vector: (AV:N/AC:H/Au:N/C:C/I:C/A:C).

Overview

First reported 18 years ago

2006-08-21 20:04:00

Last updated 6 years ago

2018-10-17 21:34:00

Affected Software

Mozilla Firefox 0.8

0.8

Mozilla Firefox 0.9

0.9

Mozilla Firefox 0.9 rc

0.9

Mozilla Firefox 0.9.1

0.9.1

Mozilla Firefox 0.9.2

0.9.2

Mozilla Firefox 0.9.3

0.9.3

Mozilla Firefox 0.10

0.10

Mozilla Firefox 0.10.1

0.10.1

Mozilla Firefox 1.0

1.0

Mozilla Firefox 1.0.1

1.0.1

Mozilla Firefox 1.0.2

1.0.2

Mozilla Firefox 1.0.3

1.0.3

Mozilla Firefox 1.0.4

1.0.4

Mozilla Firefox 1.0.5

1.0.5

Mozilla Firefox 1.0.6

1.0.6

Mozilla Firefox 1.0.7

1.0.7

Mozilla Firefox 1.0.8

1.0.8

Mozilla Firefox 1.5

1.5

Mozilla Firefox 1.5 Beta 1

1.5

Mozilla Firefox 1.5 Beta 2

1.5

Mozilla Firefox 1.5.0.1

1.5.0.1

Mozilla Firefox 1.5.0.2

1.5.0.2

Mozilla Firefox 1.5.0.3

1.5.0.3

Mozilla Firefox 1.5.0.4

1.5.0.4

Mozilla Firefox 1.5.0.5

1.5.0.5

Mozilla Firefox 1.5.0.6

1.5.0.6

Netscape Netscape 8.1

8.1

References

20060901-01-P

http://lcamtuf.coredump.cx/ffoxdie.html

http://lcamtuf.coredump.cx/ffoxdie3.html

21513

Vendor Advisory

21906

Vendor Advisory

21915

Vendor Advisory

21916

Vendor Advisory

21939

Vendor Advisory

21940

Vendor Advisory

21949

Vendor Advisory

21950

Vendor Advisory

22001

Vendor Advisory

22025

Vendor Advisory

22036

Vendor Advisory

22055

Vendor Advisory

22056

22066

22074

Vendor Advisory

22088

Vendor Advisory

22195

22210

Vendor Advisory

22274

Vendor Advisory

22391

Vendor Advisory

22422

Vendor Advisory

24711

GLSA-200609-19

GLSA-200610-01

GLSA-200610-04

1016846

1016847

1016848

http://support.avaya.com/elmodocs2/security/ASA-2006-224.htm

MDKSA-2006:168

MDKSA-2006:169

http://www.mozilla.org/security/announce/2006/mfsa2006-59.html

SUSE-SA:2006:054

http://www.pianetapc.it/view.php?id=770

RHSA-2006:0675

RHSA-2006:0676

RHSA-2006:0677

http://www.securiteam.com/securitynews/5VP0M0AJFW.html

20060812 Concurrency-related vulnerabilities in browsers - expect problems

20060815 Re: Concurrency-related vulnerabilities in browsers - expect problems

20060817 Re: [VulnWatch] Re: Concurrency-related vulnerabilities in browsers - expect problems

20060817 RE: [VulnWatch] Re: Concurrency-related vulnerabilities in browsers - expect problems

20060915 rPSA-2006-0169-1 firefox thunderbird

20061006 Re: Concurrency-related vulnerabilities in browsers - expect problems

20061005 Re: Concurrency-related vulnerabilities in browsers - expect problems

20061017 Flaw in Firefox 2.0 RC2

20061017 Re: Flaw in Firefox 2.0 RC2

20061019 Re: Flaw in Firefox 2.0 RC2

20061023 Flaw in Firefox 2.0 Final

20061025 Mozilla Firefox JavaScript Handler Race Condition Memory Corruption Vulnerability

19488

19534

USN-350-1

USN-351-1

USN-352-1

USN-354-1

ADV-2006-3617

ADV-2006-3748

ADV-2007-1198

ADV-2008-0083

SSRT061181

https://bugzilla.mozilla.org/show_bug.cgi?id=348514

https://issues.rpath.com/browse/RPL-640

oval:org.mitre.oval:def:9528

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.