National Cyber Alert System<br /><br /> Cyber Security Alert SA06-038A<br /><br /><br />Multiple Vulnerabilities in Mozilla Products<br /><br /> Original release date: February 7, 2006<br /> Last revised: --<br /> Source: US-CERT<br /><br /><br />Systems Affected<br /><br /> * Mozilla web browser<br /> * Mozilla mail client<br /> * Firefox web browser<br /> * Thunderbird mail client<br /><br /><br />Overview<br /><br /> By taking advantage of one or more vulnerabilities in Mozilla<br /> products, an attacker may be able to take control of your computer.<br /><br /><br />Solution<br /><br />Upgrade to the latest version of Firefox<br /><br /> Mozilla has released an updated version of Firefox to correct these<br /> problems.<br /><br /><br />Description<br /><br /> There are vulnerabilities in various features of the Mozilla web<br /> browser, Mozilla email client, Firefox web browser, and Thunderbird<br /> email client. Some of the vulnerabilities are connected to the way<br /> the application handles URLs or images. In one instance, an<br /> attacker could cause an application to crash or could take control<br /> of your computer by convincing you to view a malicious web site or<br /> email message.<br /><br /> For more technical information, see US-CERT Technical Alert<br /> TA06-038A.<br /><br /><br />References<br /><br /> * Mozilla Foundation Security Advisory 2006-04 -<br /> <http://www.mozilla.org/security/announce/mfsa206-04.html><br /><br /> * US-CERT Technical Cyber Security Alert TA06-038A -<br /> <http://www.us-cert.gov/cas/techalerts/TA05-038A.html><br /><br /> * US-CERT Vulnerability Note VU#592425 -<br /> <http://www.kb.cert.org/vuls/id/592425><br /><br /> * US-CERT Vulnerability Note VU#759273 -<br /> <http://www.kb.cert.org/vuls/id/759273><br /><br /><br /> ____________________________________________________________________<br /><br /> The most recent version of this document can be found at:<br /><br /> <http://www.us-cert.gov/cas/alerts/SA06-038A.html><br /> ____________________________________________________________________<br /><br /> Feedback can be directed to US-CERT. Please send email to<br /> <cert@cert.org> with "SA06-038A Feedback VU#592425" in the subject.<br /> ____________________________________________________________________<br /><br /> Mailing list information:<br /><br /> <http://www.us-cert.gov/cas/><br /> ____________________________________________________________________<br /><br /> Produced 2006 by US-CERT, a government organization.<br /><br /> Terms of use:<br /><br /> <http://www.us-cert.gov/legal.html><br /> ____________________________________________________________________<br /><br /><br />Revision History<br /><br /> February 7, 2006: Initial release