FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-2968

This CVE name corresponds to:

Entered Topic
2005-09-22 firefox & mozilla -- command line URL shell command injection

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-2968
Phase Assigned(20050919)

Description

Firefox 1.0.6 and Mozilla 1.7.10 allows attackers to execute arbitrary commands via shell metacharacters in a URL that is provided to the browser on the command line, which is sent unfiltered to bash.

References

Source Reference
CONFIRM http://www.mozilla.org/security/announce/mfsa2005-58.html
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=307185
DEBIAN DSA-868
DEBIAN DSA-866
MANDRIVA MDKSA-2005:174
REDHAT RHSA-2005:785
REDHAT RHSA-2005:791
SCO SCOSA-2005.49
UBUNTU USN-186-1
UBUNTU USN-186-2
UBUNTU USN-200-1
CERT-VN VU#914681
BID 15495
BID 14888
OVAL oval:org.mitre.oval:def:11105
VUPEN ADV-2005-1794
VUPEN ADV-2005-1824
SECUNIA 16869
SECUNIA 17042
SECUNIA 17090
SECUNIA 17149
SECUNIA 17284
SECUNIA 17263