Mozilla Firefox XML User Interface Language Browser Interface Spoofing Vulnerability
BID:10832
Info
Mozilla Firefox XML User Interface Language Browser Interface Spoofing Vulnerability
| Bugtraq ID: | 10832 |
| Class: | Design Error |
| CVE: |
CVE-2004-0764 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 30 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | Discovery of this vulnerability is credited to Jeff <[email protected]>. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 SuSE Linux Enterprise Server 9 SuSE Linux Desktop 1.0 SuSE Linux 8.1 SGI Advanced Linux Environment 3.0 SCO Unixware 7.1.4 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 Redhat Linux 9.0 i386 Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Fedora Core1 Mozilla Firefox 1.0 Mozilla Firefox 0.10.1 Mozilla Firefox 0.10 Mozilla Firefox 0.9.3 Mozilla Firefox 0.9.2 Mozilla Firefox 0.9.1 Mozilla Firefox 0.9 rc Mozilla Firefox 0.9 Mozilla Firefox 0.8 Mozilla Firefox Preview Release Mozilla Browser 1.7.1 Mozilla Browser 1.7 rc3 Mozilla Browser 1.7 Mozilla Browser 1.6 Mozilla Browser 1.5 Mozilla Browser 1.4.2 Mozilla Browser 1.4.1 Mozilla Browser 1.4 b Mozilla Browser 1.4 a Mozilla Browser 1.4 Mozilla Browser 1.3.1 Mozilla Browser 1.3 Mozilla Browser 1.2.1 Mozilla Browser 1.2 Beta Mozilla Browser 1.2 Alpha Mozilla Browser 1.2 Mozilla Browser 1.1 Beta Mozilla Browser 1.1 Alpha Mozilla Browser 1.1 Mozilla Browser 1.0.2 Mozilla Browser 1.0.1 Mozilla Browser 1.0 RC2 Mozilla Browser 1.0 RC1 Mozilla Browser 1.0 |
| Not Vulnerable: |
Mozilla Firefox 1.0.1 |
Discussion
Mozilla Firefox XML User Interface Language Browser Interface Spoofing Vulnerability
Mozilla Firefox is reported prone to an interface spoofing vulnerability. The issue presents itself because JavaScript code is allowed to hide the Mozilla Firefox interface and status bar by default. A fake Mozilla firefox interface may be created using the XML User Interface Language API, this interface may aid in phishing style attacks.
This misrepresentation may fool a user into trusting a malicious site, which would likely ask the user to submit sensitive or private information.
Mozilla Firefox is reported prone to an interface spoofing vulnerability. The issue presents itself because JavaScript code is allowed to hide the Mozilla Firefox interface and status bar by default. A fake Mozilla firefox interface may be created using the XML User Interface Language API, this interface may aid in phishing style attacks.
This misrepresentation may fool a user into trusting a malicious site, which would likely ask the user to submit sensitive or private information.
Exploit / POC
Mozilla Firefox XML User Interface Language Browser Interface Spoofing Vulnerability
Proof of concept code is available at the following location, it should be noted that Symantec does not verify the integrity of this example:
http://www.nd.edu/~jsmith30/xul/test/spoof.html
Proof of concept code is available at the following location, it should be noted that Symantec does not verify the integrity of this example:
http://www.nd.edu/~jsmith30/xul/test/spoof.html
Solution / Fix
Mozilla Firefox XML User Interface Language Browser Interface Spoofing Vulnerability
Solution:
Conectiva has released an advisory (CLA-2004:877) to address various issues including this issue in Mozilla. This advisory contains updated Mozilla packages (1.7.3) for Conectiva Linux 9 and 10. Please see the referenced advisory for more information.
SCO has released an advisory SCOSA-2005.25 including updated packages to address this issue. Please see the referenced advisory for more information.
Slackware has released an advisory (SSA:2004-223-01) to address this issue. Please see the referenced advisory for more information.
SGI has made available Patch 10095, correcting this vulnerability for systems running SGI Advanced Linux Environment 3:
Patch 10095 is available from http://support.sgi.com/ and
ftp://patches.sgi.com/support/free/security/patches/ProPack/3/
The individual RPMs from Patch 10095 are available from:
ftp://oss.sgi.com/projects/sgi_propack/download/3/updates/RPMS
ftp://oss.sgi.com/projects/sgi_propack/download/3/updates/SRPMS
SuSE Linux has released advisory SUSE-SA:2004:036 along with fixes dealing with this issue. Please see the referenced advisory for more information.
The Fedora Legacy project has released advisory FLSA-2004:2089 along with fixes to address multiple issues in RedHat Fedora Core 1, and RedHat Linux 7.3 and 9.0. Please see the referenced advisory for further information.
Mozilla has released version 1.0.1 of Firefox to address this, and other issues.
Mozilla Firefox Preview Release
Mozilla Firefox 0.10
Mozilla Firefox 0.10.1
Mozilla Firefox 0.8
Mozilla Firefox 0.9
Mozilla Firefox 0.9 rc
Mozilla Firefox 0.9.1
Mozilla Firefox 0.9.2
Mozilla Firefox 0.9.3
Mozilla Firefox 1.0
Mozilla Browser 1.2.1
Mozilla Browser 1.4
Mozilla Browser 1.4.1
Mozilla Browser 1.6
Mozilla Browser 1.7
Solution:
Conectiva has released an advisory (CLA-2004:877) to address various issues including this issue in Mozilla. This advisory contains updated Mozilla packages (1.7.3) for Conectiva Linux 9 and 10. Please see the referenced advisory for more information.
SCO has released an advisory SCOSA-2005.25 including updated packages to address this issue. Please see the referenced advisory for more information.
Slackware has released an advisory (SSA:2004-223-01) to address this issue. Please see the referenced advisory for more information.
SGI has made available Patch 10095, correcting this vulnerability for systems running SGI Advanced Linux Environment 3:
Patch 10095 is available from http://support.sgi.com/ and
ftp://patches.sgi.com/support/free/security/patches/ProPack/3/
The individual RPMs from Patch 10095 are available from:
ftp://oss.sgi.com/projects/sgi_propack/download/3/updates/RPMS
ftp://oss.sgi.com/projects/sgi_propack/download/3/updates/SRPMS
SuSE Linux has released advisory SUSE-SA:2004:036 along with fixes dealing with this issue. Please see the referenced advisory for more information.
The Fedora Legacy project has released advisory FLSA-2004:2089 along with fixes to address multiple issues in RedHat Fedora Core 1, and RedHat Linux 7.3 and 9.0. Please see the referenced advisory for further information.
Mozilla has released version 1.0.1 of Firefox to address this, and other issues.
Mozilla Firefox Preview Release
-
Mozilla firefox-1.0.1-source.tar.bz2
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/1.0.1/source/f irefox-1.0.1-source.tar.bz2
Mozilla Firefox 0.10
-
Mozilla firefox-1.0.1-source.tar.bz2
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/1.0.1/source/f irefox-1.0.1-source.tar.bz2
Mozilla Firefox 0.10.1
-
Mozilla firefox-1.0.1-source.tar.bz2
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/1.0.1/source/f irefox-1.0.1-source.tar.bz2
Mozilla Firefox 0.8
-
Mozilla firefox-1.0.1-source.tar.bz2
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/1.0.1/source/f irefox-1.0.1-source.tar.bz2
Mozilla Firefox 0.9
-
Mozilla firefox-1.0.1-source.tar.bz2
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/1.0.1/source/f irefox-1.0.1-source.tar.bz2
Mozilla Firefox 0.9 rc
-
Mozilla firefox-1.0.1-source.tar.bz2
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/1.0.1/source/f irefox-1.0.1-source.tar.bz2
Mozilla Firefox 0.9.1
-
Mozilla firefox-1.0.1-source.tar.bz2
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/1.0.1/source/f irefox-1.0.1-source.tar.bz2
Mozilla Firefox 0.9.2
-
Mozilla firefox-1.0.1-source.tar.bz2
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/1.0.1/source/f irefox-1.0.1-source.tar.bz2
Mozilla Firefox 0.9.3
-
Mozilla firefox-1.0.1-source.tar.bz2
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/1.0.1/source/f irefox-1.0.1-source.tar.bz2
Mozilla Firefox 1.0
-
Mozilla firefox-1.0.1-source.tar.bz2
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/1.0.1/source/f irefox-1.0.1-source.tar.bz2
Mozilla Browser 1.2.1
-
RedHat galeon-1.2.13-0.9.2.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/galeon-1.2.13-0 .9.2.legacy.i386.rpm -
RedHat mozilla-1.4.3-0.9.1.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-1.4.3-0 .9.1.legacy.i386.rpm -
RedHat mozilla-chat-1.4.3-0.9.1.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-chat-1. 4.3-0.9.1.legacy.i386.rpm -
RedHat mozilla-devel-1.4.3-0.9.1.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-devel-1 .4.3-0.9.1.legacy.i386.rpm -
RedHat mozilla-dom-inspector-1.4.3-0.9.1.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-dom-ins pector-1.4.3-0.9.1.legacy.i386.rpm -
RedHat mozilla-js-debugger-1.4.3-0.9.1.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-js-debu gger-1.4.3-0.9.1.legacy.i386.rpm -
RedHat mozilla-mail-1.4.3-0.9.1.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-mail-1. 4.3-0.9.1.legacy.i386.rpm -
RedHat mozilla-nspr-1.4.3-0.9.1.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-nspr-1. 4.3-0.9.1.legacy.i386.rpm -
RedHat mozilla-nspr-devel-1.4.3-0.9.1.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-nspr-de vel-1.4.3-0.9.1.legacy.i386.rpm -
RedHat mozilla-nss-1.4.3-0.9.1.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-nss-1.4 .3-0.9.1.legacy.i386.rpm -
RedHat mozilla-nss-devel-1.4.3-0.9.1.legacy.i386.rpm
RedHat Linux 9
http://download.fedoralegacy.org/redhat/9/updates/i386/mozilla-nss-dev el-1.4.3-0.9.1.legacy.i386.rpm
Mozilla Browser 1.4
-
Slackware mozilla-1.4.3-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/m ozilla-1.4.3-i486-1.tgz -
Slackware mozilla-plugins-1.4.3-noarch-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/m ozilla-plugins-1.4.3-noarch-1.tgz
Mozilla Browser 1.4.1
-
RedHat epiphany-1.0.4-2.4.legacy.i386.rpm
RedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/epiphany-1.0.4- 2.4.legacy.i386.rpm -
RedHat mozilla-1.4.3-1.fc1.1.legacy.i386.rpm
RedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-1.4.3-1 .fc1.1.legacy.i386.rpm -
RedHat mozilla-chat-1.4.3-1.fc1.1.legacy.i386.rpm
RedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-chat-1. 4.3-1.fc1.1.legacy.i386.rpm -
RedHat mozilla-devel-1.4.3-1.fc1.1.legacy.i386.rpm
RedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-devel-1 .4.3-1.fc1.1.legacy.i386.rpm -
RedHat mozilla-dom-inspector-1.4.3-1.fc1.1.legacy.i386.rpm
RedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-dom-ins pector-1.4.3-1.fc1.1.legacy.i386.rpm -
RedHat mozilla-js-debugger-1.4.3-1.fc1.1.legacy.i386.rpm
RedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-js-debu gger-1.4.3-1.fc1.1.legacy.i386.rpm -
RedHat mozilla-mail-1.4.3-1.fc1.1.legacy.i386.rpm
RedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-mail-1. 4.3-1.fc1.1.legacy.i386.rpm -
RedHat mozilla-nspr-1.4.3-1.fc1.1.legacy.i386.rpm
RedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-nspr-1. 4.3-1.fc1.1.legacy.i386.rpm -
RedHat mozilla-nspr-devel-1.4.3-1.fc1.1.legacy.i386.rpm
RedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-nspr-de vel-1.4.3-1.fc1.1.legacy.i386.rpm -
RedHat mozilla-nss-1.4.3-1.fc1.1.legacy.i386.rpm
RedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-nss-1.4 .3-1.fc1.1.legacy.i386.rpm -
RedHat mozilla-nss-devel-1.4.3-1.fc1.1.legacy.i386.rpm
RedHat Fedora Core 1
http://download.fedoralegacy.org/fedora/1/updates/i386/mozilla-nss-dev el-1.4.3-1.fc1.1.legacy.i386.rpm
Mozilla Browser 1.6
-
Conectiva libnspr-devel-1.7.3-27852U90_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libnspr-devel-1.7.3-27852U9 0_4cl.i386.rpm -
Conectiva libnspr-devel-1.7.3-60868U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/libnspr-devel-1.7.3-60868U 10_1cl.i386.rpm -
Conectiva libnspr4-1.7.3-27852U90_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libnspr4-1.7.3-27852U90_4cl .i386.rpm -
Conectiva libnspr4-1.7.3-60868U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/libnspr4-1.7.3-60868U10_1c l.i386.rpm -
Conectiva libnss-devel-1.7.3-27852U90_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libnss-devel-1.7.3-27852U90 _4cl.i386.rpm -
Conectiva libnss-devel-1.7.3-60868U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/libnss-devel-1.7.3-60868U1 0_1cl.i386.rpm -
Conectiva libnss3-1.7.3-27852U90_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libnss3-1.7.3-27852U90_4cl. i386.rpm -
Conectiva libnss3-1.7.3-60868U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/libnss3-1.7.3-60868U10_1cl .i386.rpm -
Conectiva mozilla-1.7.3-27852U90_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mozilla-1.7.3-27852U90_4cl. i386.rpm -
Conectiva mozilla-1.7.3-60868U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mozilla-1.7.3-60868U10_1cl .i386.rpm -
Conectiva mozilla-base-1.7.3-27852U90_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mozilla-base-1.7.3-27852U90 _4cl.i386.rpm -
Conectiva mozilla-base-1.7.3-60868U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mozilla-base-1.7.3-60868U1 0_1cl.i386.rpm -
Conectiva mozilla-devel-1.7.3-27852U90_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mozilla-devel-1.7.3-27852U9 0_4cl.i386.rpm -
Conectiva mozilla-devel-1.7.3-60868U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mozilla-devel-1.7.3-60868U 10_1cl.i386.rpm -
Conectiva mozilla-dom-inspector-1.7.3-27852U90_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mozilla-dom-inspector-1.7.3 -27852U90_4cl.i386.rpm -
Conectiva mozilla-dom-inspector-1.7.3-60868U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mozilla-dom-inspector-1.7. 3-60868U10_1cl.i386.rpm -
Conectiva mozilla-irc-1.7.3-27852U90_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mozilla-irc-1.7.3-27852U90_ 4cl.i386.rpm -
Conectiva mozilla-irc-1.7.3-60868U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mozilla-irc-1.7.3-60868U10 _1cl.i386.rpm -
Conectiva mozilla-js-debugger-1.7.3-27852U90_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mozilla-js-debugger-1.7.3-2 7852U90_4cl.i386.rpm -
Conectiva mozilla-js-debugger-1.7.3-60868U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mozilla-js-debugger-1.7.3- 60868U10_1cl.i386.rpm -
Conectiva mozilla-mail-1.7.3-27852U90_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mozilla-mail-1.7.3-27852U90 _4cl.i386.rpm -
Conectiva mozilla-mail-1.7.3-60868U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mozilla-mail-1.7.3-60868U1 0_1cl.i386.rpm -
Conectiva mozilla-psm-1.7.3-27852U90_4cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mozilla-psm-1.7.3-27852U90_ 4cl.i386.rpm -
Conectiva mozilla-psm-1.7.3-60868U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mozilla-psm-1.7.3-60868U10 _1cl.i386.rpm
Mozilla Browser 1.7
-
Slackware epiphany-1.2.7-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/ epiphany-1.2.7-i486-1.tgz -
Slackware gaim-0.81-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/ gaim-0.81-i486-1.tgz -
Slackware galeon-1.3.17-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/ galeon-1.3.17-i486-1.tgz -
Slackware mozilla-1.7.2-i486-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/ mozilla-1.7.2-i486-1.tgz -
Slackware mozilla-plugins-1.7.2-noarch-1.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/ mozilla-plugins-1.7.2-noarch-1.tgz
References
Mozilla Firefox XML User Interface Language Browser Interface Spoofing Vulnerability
References:
References:
- Bugzilla Bug 22183 - UI spoofing can cause user to mistake content for chrome (Mozilla)
- Firefox Release Notes (Mozilla)
- Spoof (Jeff
)