CVE-2006-0296

Impact:
Important
Public Date:
2006-02-02
Bugzilla:
1617880: CVE-2006-0296 security flaw

The MITRE CVE dictionary describes this issue as:

The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf file.

Find out more about CVE-2006-0296 from the MITRE CVE dictionary dictionary and NIST NVD.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 2.1 (mozilla) RHSA-2006:0199 2006-02-02
Red Hat Enterprise Linux 4 (mozilla) RHSA-2006:0199 2006-02-02
Red Hat Enterprise Linux 4 (thunderbird) RHSA-2006:0330 2006-04-21
Red Hat Enterprise Linux 3 (mozilla) RHSA-2006:0199 2006-02-02
Red Hat Enterprise Linux 4 (firefox) RHSA-2006:0200 2006-02-02

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.