Name | CVE-2006-6498 |
Description | Multiple unspecified vulnerabilities in the JavaScript engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, SeaMonkey before 1.0.7, and Mozilla 1.7 and probably earlier on Solaris, allow remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via unknown impact and attack vectors. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-1253-1, DSA-1258-1, DSA-1265-1 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
firefox (PTS) | sid | 131.0-1 | fixed |
firefox-esr (PTS) | bullseye | 115.14.0esr-1~deb11u1 | fixed |
bullseye (security) | 128.3.0esr-1~deb11u1 | fixed | |
bookworm | 115.14.0esr-1~deb12u1 | fixed | |
bookworm (security) | 128.3.0esr-1~deb12u1 | fixed | |
trixie | 115.15.0esr-1 | fixed | |
sid | 128.3.0esr-2 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
firefox | source | (unstable) | 45.0-1 | high | ||
firefox-esr | source | (unstable) | 45.0esr-1 | high | ||
iceape | source | (unstable) | 1.0.7-1 | high | ||
icedove | source | (unstable) | 1.5.0.9.dfsg1-1 | low | ||
iceweasel | source | (unstable) | 2.0.0.1+dfsg-1 | high | ||
mozilla | source | sarge | 2:1.7.8-1sarge10 | DSA-1265-1 | ||
mozilla | source | (unstable) | (unfixed) | high | ||
mozilla-firefox | source | sarge | 1.0.4-2sarge15 | DSA-1253-1 | ||
mozilla-firefox | source | (unstable) | (unfixed) | high | ||
mozilla-thunderbird | source | sarge | 1.0.2-2.sarge1.0.8e.2 | DSA-1258-1 | ||
mozilla-thunderbird | source | (unstable) | (unfixed) | low | ||
xulrunner | source | (unstable) | 1.8.0.9-1 | high |
MFSA-2006-68