Mozilla Browser Cross-Domain Dialog Box Spoofing Vulnerability
BID:11473
Info
Mozilla Browser Cross-Domain Dialog Box Spoofing Vulnerability
| Bugtraq ID: | 11473 |
| Class: | Access Validation Error |
| CVE: |
CVE-2004-1380 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 20 2004 12:00AM |
| Updated: | Jul 12 2009 08:06AM |
| Credit: | Discovery of this vulnerability is credited to Jakob Balle of Secunia Research. |
| Vulnerable: |
SGI ProPack 3.0 Redhat Linux 9.0 i386 Redhat Linux 7.3 i686 Redhat Linux 7.3 i386 Redhat Linux 7.3 Redhat Fedora Core2 Redhat Fedora Core1 Netscape Netscape 7.2 Netscape Netscape 7.1 Netscape Netscape 7.0 Netscape Navigator 7.2 Mozilla Firefox 1.0 Mozilla Firefox 0.10.1 Mozilla Camino 0.8 Mozilla Browser 1.7.6 Mozilla Browser 1.7.3 Mozilla Browser 1.7.2 Mozilla Browser 1.4.4 GNOME Epiphany 1.4.4 GNOME Epiphany 1.4 GNOME Epiphany 1.2.9 GNOME Epiphany 1.2 Galeon Galeon Browser 1.3.18 Galeon Galeon Browser 1.2.13 Galeon Galeon Browser 1.2.7 Galeon Galeon Browser 1.2.6 Galeon Galeon Browser 1.2.5 Galeon Galeon Browser 1.2.4 Galeon Galeon Browser 1.2.3 Galeon Galeon Browser 1.2.2 |
| Not Vulnerable: |
Netscape Netscape 8.0 Mozilla Firefox 1.0.1 |
Discussion
Mozilla Browser Cross-Domain Dialog Box Spoofing Vulnerability
Mozilla Browsers are reported prone to a cross-domain dialog box spoofing vulnerability. This issue may allow a remote attacker to carry out phishing style attacks as an attacker may exploit this vulnerability to spoof an interface of a trusted web site.
Due to code similarities, Netscape Navigator is affected by this issue as well.
Mozilla Browsers are reported prone to a cross-domain dialog box spoofing vulnerability. This issue may allow a remote attacker to carry out phishing style attacks as an attacker may exploit this vulnerability to spoof an interface of a trusted web site.
Due to code similarities, Netscape Navigator is affected by this issue as well.
Exploit / POC
Mozilla Browser Cross-Domain Dialog Box Spoofing Vulnerability
An exploit is not required.
A proof of concept is available from the following location:
http://secunia.com/multiple_browsers_dialog_box_spoofing_test/
An exploit is not required.
A proof of concept is available from the following location:
http://secunia.com/multiple_browsers_dialog_box_spoofing_test/
Solution / Fix
Mozilla Browser Cross-Domain Dialog Box Spoofing Vulnerability
Solution:
Mozilla has released version 1.0.1 of Firefox to address this, and other issues:
SGI has released an advisory 20050304-01-U including updated SGI ProPack 3 Service Pack 4 packages to address this issue. Please see the referenced advisory for more information.
Slackware Linux has released advisory SSA:2005-085-01 along with fixes dealing with this issue. Please see the reference section for more information.
RedHat has released advisories RHSA-2005:323 and RHSA-2005:335 to address this issue. Please see the referenced advisories to obtain fix information.
RedHat Fedora Legacy has released advisory FLSA:152883 addressing this and other issues for RedHat Linux 7.3, 9 and for Fedora Core 1 and Core 2. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Netscape Browser 8.0 has been released to address various security issues.
Please see the vendor advisory in Web references for more information.
Mozilla Firefox 0.10.1
Mozilla Firefox 1.0
Netscape Netscape 7.0
Netscape Netscape 7.1
Netscape Netscape 7.2
Solution:
Mozilla has released version 1.0.1 of Firefox to address this, and other issues:
SGI has released an advisory 20050304-01-U including updated SGI ProPack 3 Service Pack 4 packages to address this issue. Please see the referenced advisory for more information.
Slackware Linux has released advisory SSA:2005-085-01 along with fixes dealing with this issue. Please see the reference section for more information.
RedHat has released advisories RHSA-2005:323 and RHSA-2005:335 to address this issue. Please see the referenced advisories to obtain fix information.
RedHat Fedora Legacy has released advisory FLSA:152883 addressing this and other issues for RedHat Linux 7.3, 9 and for Fedora Core 1 and Core 2. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Netscape Browser 8.0 has been released to address various security issues.
Please see the vendor advisory in Web references for more information.
Mozilla Firefox 0.10.1
-
Mozilla firefox-1.0.1-source.tar.bz2
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/1.0.1/source/f irefox-1.0.1-source.tar.bz2
Mozilla Firefox 1.0
-
Mozilla firefox-1.0.1-source.tar.bz2
http://ftp.mozilla.org/pub/mozilla.org/firefox/releases/1.0.1/source/f irefox-1.0.1-source.tar.bz2
Netscape Netscape 7.0
-
Netscape Netscape 8.0
http://browser.netscape.com/ns8/download/
Netscape Netscape 7.1
-
Netscape Netscape 8.0
http://browser.netscape.com/ns8/download/
Netscape Netscape 7.2
-
Netscape Netscape 8.0
http://browser.netscape.com/ns8/download/
References
Mozilla Browser Cross-Domain Dialog Box Spoofing Vulnerability
References:
References:
- Camino Project Product Page (Mozilla)
- Firefox Release Notes (Mozilla)
- Galeon Homepage (Galeon)
- Gnome Epiphany Homepage (GNOME)
- Mozilla / Mozilla Firefox / Camino Tabbed Browsing Vulnerabilities (Secunia)
- Mozilla Homepage (Mozilla Foundation)
- Multiple Browsers Tabbed Browsing Vulnerabilities (Secunia)
- Netscape Homepage (Netscape)
- RHSA-2005:323-10 Critical: mozilla security update (RedHat)
- RHSA-2005:335-07 Critical: mozilla security update (RedHat)
- Security Alerts (Netscape)
- SSA:2005-085-01 - Mozilla/Firefox/Thunderbird (Slackware)