CVE-2006-6585 Affecting firefox-esr package, versions <45.0esr-1


0.0
medium

Snyk CVSS

    Attack Complexity Low

    Threat Intelligence

    EPSS 0.22% (60th percentile)
Expand this section
NVD
6.5 medium

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-DEBIANUNSTABLE-FIREFOXESR-354920
  • published 15 Dec 2006
  • disclosed 15 Dec 2006

How to fix?

Upgrade Debian:unstable firefox-esr to version 45.0esr-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream firefox-esr package and not the firefox-esr package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

The Extensions manager in Mozilla Firefox 2.0 does not properly populate the list of local extensions, which allows attackers to construct an extension that hides itself by finding its name in the list and then calling RemoveElement, as demonstrated by the FFsniFF extension. NOTE: it was later reported that 3.0 is also affected.