CVE-2006-2786

NameCVE-2006-2786
DescriptionHTTP response smuggling vulnerability in Mozilla Firefox and Thunderbird before 1.5.0.4, when used with certain proxy servers, allows remote attackers to cause Firefox to interpret certain responses as if they were responses from two different sites via (1) invalid HTTP response headers with spaces between the header name and the colon, which might not be ignored in some cases, or (2) HTTP 1.1 headers through an HTTP 1.0 proxy, which are ignored by the proxy but processed by the client.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-1118, DSA-1120, DSA-1134-1
NVD severitylow (attack range: remote)
Debian/oldoldstablenot known to be vulnerable.
Debian/oldstablenot vulnerable.
Debian/stablenot known to be vulnerable.
Debian/testingnot known to be vulnerable.
Debian/unstablenot known to be vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
xulrunner (PTS)wheezy (security), wheezy24.8.1esr-2~deb7u1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
firefoxsource(unstable)1.5.dfsg+1.5.0.4-1medium
mozillasource(unstable)2:1.7.13-0.3medium
mozillasourcesarge2:1.7.8-1sarge7.1lowDSA-1118
mozilla-firefoxsourcesarge1.0.4-2sarge9lowDSA-1120
mozilla-thunderbirdsourcesarge1.0.2-2.sarge1.0.8alowDSA-1134-1
thunderbirdsource(unstable)1.5.0.4-1medium
xulrunnersource(unstable)1.8.0.4-1medium

Notes

MFSA-2006-33

Search for package or bug name: Reporting problems