Intrusion Prevention

Mozilla.Firefox.Frame.Reference.Remote.Code.Execution

Description

This indicates an attack attempt against a remote Code Execution vulnerability in Mozilla Firefox.
The vulnerability is caused by an error when the vulnerable software does not properly clear a JavaScript reference to a frame or window. It allows a remote attacker to execute arbitrary code.

Affected Products

Mozilla Firefox version 1.5.0.4 and previous versions.

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.
Denial of Service: Remote attackers can crash vulnerable systems.

Recommended Actions

Upgrade to Firefox 1.5.0.5 or newer:
http://www.mozilla.org/firefox/

CVE References

CVE-2006-3801