Overview
Mozilla products contain a buffer overflow in the crypto.signText() method. This may allow a remote attacker to execute arbitrary code.
Description
crypto.SignText() JavaScript contains a crypto.signText() method, which allows the user to digitally sign a text string.  | 
Impact
By convincing a user to view a specially crafted HTML document (e.g., a web page, an HTML email message, or an HTML email attachment), an attacker may be able to execute arbitrary code with the privileges of the user.  | 
Solution
Apply an update  | 
  | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental | 
References
Acknowledgements
Thanks to the Mozilla Foundation Security Advisory for reporting this vulnerability, who in turn credit Mikolaj J. Habryn.
This document was written by Will Dormann.
Other Information
| CVE IDs: | CVE-2006-2778 | 
| Severity Metric: | 10.33 | 
| Date Public: | 2006-06-01 | 
| Date First Published: | 2006-06-02 | 
| Date Last Updated: | 2007-02-09 14:34 UTC | 
| Document Revision: | 17 |