PublicDate: 2006-06-07 10:02:00 UTC Candidate: CVE-2006-2894 References: https://ubuntu.com/security/notices/USN-536-1 https://ubuntu.com/security/notices/USN-535-1 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2894 Description: Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1.1.5, and Netscape 8.1 and earlier allow user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the OnKeyDown, OnKeyPress, and OnKeyUp Javascript keystroke events to change the focus and cause those characters to be inserted into a file upload input control, which can then upload the file when the user submits the form. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: upstream_firefox: released (1.5.0.12, 2.0.0.4) dapper_firefox: released (1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1) edgy_firefox: released (2.0.0.6+0dfsg-0ubuntu0.6.10) feisty_firefox: released (2.0.0.6+1-0ubuntu1) devel_firefox: not-affected upstream_thunderbird: released (2.0.0.8) dapper_mozilla-thunderbird: released (1.5.0.13+1.5.0.14b-0ubuntu0.6.06) edgy_mozilla-thunderbird: released (1.5.0.13+1.5.0.14b-0ubuntu0.6.10) feisty_mozilla-thunderbird: released (1.5.0.13+1.5.0.14b-0ubuntu0.7.04) gutsy_thunderbird: released (2.0.0.8~pre071022+nobinonly-0ubuntu0.7.10) devel_thunderbird: not-affected upstream_mozilla-thunderbird: needs-triage