Mozilla Products Contain Multiple Vulnerabilities
Systems Affected
- Mozilla SeaMonkey web browser
- Mozilla Firefox web browser
- Mozilla Thunderbird email application
- Netscape web browser
Any products based on Mozilla components may also be affected.
Overview
The Mozilla web browser and derived products contain several
vulnerabilities. By taking advantage of one or more of these
vulnerabilities, an attacker may be able to take control of your
computer.
Solution
Upgrade to the latest versions of Firefox, Thunderbird, and SeaMonkey
Mozilla has released Firefox 1.5.0.5, Thunderbird 1.5.0.5 and SeaMonkey 1.0.3 to correct these problems.
Netscape users should disable JavaScript and Java as specified in the Netscape Site Controls web page.
Description
Mozilla products, including the Firefox web browser and Thunderbird email application, contain a number of vulnerabilities. These vulnerabilities may allow an attacker to access your computer, run programs that could cause your computer to crash, or gain control of your computer.
For more technical information, see US-CERT
Technical Alert TA06-208A.
References
- US-CERT Vulnerability Notes Related to July Mozilla Security Advisories - <http://www.kb.cert.org/vuls/byid?searchview&query=firefox_1505>
- Mozilla Foundation Security Advisories - <http://www.mozilla.org/projects/security/known-vulnerabilities.html>
- Firefox - Rediscover the Web - <http://www.mozilla.com/firefox/>
- Thunderbird - Reclaim your inbox - <http://www.mozilla.com/thunderbird/>
- The SeaMonkey Project - <http://www.mozilla.org/projects/seamonkey/>
- Site Controls - <http://browser.netscape.com/ns8/help/options-site.jsp>
- Securing Your Web Browser - <http://www.us-cert.gov/reading_room/securing_browser/browser_security.html#Mozilla_Firefox>
Feedback can be directed
to US-CERT -->.
Revision History
-
July 27, 2006: Initial release
July 31, 2006: Added Netscape information
This product is provided subject to this Notification and this Privacy & Use policy.