{"vuid":"VU#447772","idnumber":"447772","name":"Mozilla JavaScript Engine multiple memory corruption vulnerabilities","keywords":["Mozilla","DoS","denial of service","memory corruption","crash","mozilla_20061219"],"overview":"Several vulnerabilities exists in the Mozilla JavaScript Engine that may allow a remote attacker to compromise a vulnerable system.","clean_desc":"The Mozilla JavaScript Engine contains multiple vulnerabilities that may result in memory corruption. According to the Mozilla Foundation Security Advisory 2006-68: Some of these were crashes that showed evidence of memory corruption and we presume that at least some of these could be exploited to run arbitrary code with enough effort.","impact":"A remote, unauthenticated attacker may be able to cause an affected application to crash, thereby causing a denial of service. The Mozilla foundation indicates that some of these underlying vulnerabilities may allow an attacker to execute arbitrary code, however the potential for this impact is unclear and has not been confirmed.","resolution":"Apply an update\nAccording to the Mozilla Foundation Security Advisory 2006-68, this vulnerability is addressed in Firefox 2.0.0.1, Firefox 1.5.0.9, Thunderbird 1.5.0.9, and SeaMonkey 1.0.7.","workarounds":"Disable JavaScript For instructions on how to disable JavaScript in Firefox, please refer to the Firefox section of the Securing Your Web Browser document.","sysaffected":"","thanks":"This issue is address in Mozilla Foundation Security Advisory \n2006-68 Mozilla credits Igor Bukanov, Jesse Ruderman and moz_bug_r_a4 with providing information about this issue.","author":"This document was written by Chris Taschner.","public":["https://bugzilla.mozilla.org/show_bug.cgi?id=352846","https://bugzilla.mozilla.org/show_bug.cgi?id=356238","https://bugzilla.mozilla.org/show_bug.cgi?id=357063","https://bugzilla.mozilla.org/show_bug.cgi?id=358192","https://bugzilla.mozilla.org/show_bug.cgi?id=362180","https://bugzilla.mozilla.org/show_bug.cgi?id=353214","https://bugzilla.mozilla.org/show_bug.cgi?id=356402","https://bugzilla.mozilla.org/show_bug.cgi?id=361346","https://bugzilla.mozilla.org/show_bug.cgi?id=361552","https://bugzilla.mozilla.org/show_bug.cgi?id=361964","http://secunia.com/advisories/23591/","http://secunia.com/advisories/23439/","http://secunia.com/advisories/23514/","http://secunia.com/advisories/23545/","http://secunia.com/advisories/23601/","http://secunia.com/advisories/23614/","http://secunia.com/advisories/23618/","http://secunia.com/advisories/23692/","http://www.securityfocus.com/bid/21668","http://secunia.com/advisories/23988/","http://www.auscert.org.au/7372","http://secunia.com/advisories/24390/"],"cveids":["CVE-2006-6498"],"certadvisory":"","uscerttechnicalalert":null,"datecreated":"2006-12-20T20:42:18Z","publicdate":"2006-12-19T00:00:00Z","datefirstpublished":"2007-01-18T18:23:38Z","dateupdated":"2007-04-05T18:48:59Z","revision":31,"vrda_d1_directreport":"0","vrda_d1_population":"3","vrda_d1_impact":"3","cam_widelyknown":"15","cam_exploitation":"0","cam_internetinfrastructure":"3","cam_population":"15","cam_impact":"3","cam_easeofexploitation":"12","cam_attackeraccessrequired":"20","cam_scorecurrent":"3.645","cam_scorecurrentwidelyknown":"4.6575","cam_scorecurrentwidelyknownexploited":"8.7075","ipprotocol":"","cvss_accessvector":"","cvss_accesscomplexity":"","cvss_authentication":null,"cvss_confidentialityimpact":"","cvss_integrityimpact":"","cvss_availabilityimpact":"","cvss_exploitablity":null,"cvss_remediationlevel":"","cvss_reportconfidence":"","cvss_collateraldamagepotential":"","cvss_targetdistribution":"","cvss_securityrequirementscr":"","cvss_securityrequirementsir":"","cvss_securityrequirementsar":"","cvss_basescore":"","cvss_basevector":"","cvss_temporalscore":"","cvss_environmentalscore":"","cvss_environmentalvector":"","metric":3.645,"vulnote":null}