Mozilla Firefox About:Blank Spoof Vulnerability
BID:22601
Info
Mozilla Firefox About:Blank Spoof Vulnerability
| Bugtraq ID: | 22601 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-1004 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 17 2007 12:00AM |
| Updated: | May 27 2008 10:13PM |
| Credit: | Michal Zalewski is credited with the discovery of this vulnerability. |
| Vulnerable: |
Mozilla Firefox 2.0 .1 Mozilla Firefox 1.5 beta 2 Mozilla Firefox 1.5 beta 1 Mozilla Firefox 1.5 .8 Mozilla Firefox 1.5 .6 Mozilla Firefox 1.5 Mozilla Firefox 1.0.8 Mozilla Firefox 1.0.7 Mozilla Firefox 1.0.6 Mozilla Firefox 1.0.5 Mozilla Firefox 1.0.5 Mozilla Firefox 1.0.4 Mozilla Firefox 1.0.3 Mozilla Firefox 1.0.2 Mozilla Firefox 1.0.1 Mozilla Firefox 1.0 Mozilla Firefox 0.10.1 Mozilla Firefox 0.10 Mozilla Firefox 0.9.3 Mozilla Firefox 0.9.2 Mozilla Firefox 0.9.1 Mozilla Firefox 0.9 rc Mozilla Firefox 0.9 Mozilla Firefox 0.8 Mozilla Firefox 2.0 Mozilla Firefox 1.5.0.9 Mozilla Firefox 1.5.0.8 Mozilla Firefox 1.5.0.7 Mozilla Firefox 1.5.0.6 Mozilla Firefox 1.5.0.5 Mozilla Firefox 1.5.0.4 Mozilla Firefox 1.5.0.3 Mozilla Firefox 1.5.0.2 Mozilla Firefox 1.5.0.2 Mozilla Firefox 1.5.0.1 |
| Not Vulnerable: |
Mozilla Firefox 2.0 .4 |
Discussion
Mozilla Firefox About:Blank Spoof Vulnerability
Mozilla Firefox is prone to a vulnerability that may allow attackers to spoof browser windows. This occurs because of a flaw in the security model of the application's JavaScript engine.
Successfully exploiting this issue may allow attackers to spoof legitimate websites in a manner that may be difficult for unsuspecting users to differentiate between them. This may aid in phishing or other social-engineering attacks.
Mozilla Firefox is prone to a vulnerability that may allow attackers to spoof browser windows. This occurs because of a flaw in the security model of the application's JavaScript engine.
Successfully exploiting this issue may allow attackers to spoof legitimate websites in a manner that may be difficult for unsuspecting users to differentiate between them. This may aid in phishing or other social-engineering attacks.
Exploit / POC
Mozilla Firefox About:Blank Spoof Vulnerability
An attacker can exploit this issue through a web client.
The following web page demonstrates this issue:
http://lcamtuf.coredump.cx/ffblank/
An attacker can exploit this issue through a web client.
The following web page demonstrates this issue:
http://lcamtuf.coredump.cx/ffblank/
Solution / Fix
Mozilla Firefox About:Blank Spoof Vulnerability
Solution:
This issue is fixed in Firefox 2.0.0.4. Please see the references for more information.
Mozilla Firefox 2.0
Mozilla Firefox 2.0 .1
Solution:
This issue is fixed in Firefox 2.0.0.4. Please see the references for more information.
Mozilla Firefox 2.0
-
Mozilla Firefox-2.0.0.4 for Linux
http://www.mozilla.com/products/download.html?product=firefox-2.0.0.4& os=linux&lang=en-US -
Mozilla Firefox-2.0.0.4 for Mac OS X
http://www.mozilla.com/products/download.html?product=firefox-2.0.0.4& os=osx&lang=en-US -
Mozilla Firefox-2.0.0.4 for Windows
http://www.mozilla.com/products/download.html?product=firefox-2.0.0.4& os=win&lang=en-US -
Mozilla Mozilla Firefox 2.0.0.4
http://www.mozilla.com/en-US/firefox/all.html
Mozilla Firefox 2.0 .1
-
Mozilla Firefox-2.0.0.4 for Linux
http://www.mozilla.com/products/download.html?product=firefox-2.0.0.4& os=linux&lang=en-US -
Mozilla Firefox-2.0.0.4 for Mac OS X
http://www.mozilla.com/products/download.html?product=firefox-2.0.0.4& os=osx&lang=en-US -
Mozilla Firefox-2.0.0.4 for Windows
http://www.mozilla.com/products/download.html?product=firefox-2.0.0.4& os=win&lang=en-US -
Mozilla Mozilla Firefox 2.0.0.4
http://www.mozilla.com/en-US/firefox/all.html
References
Mozilla Firefox About:Blank Spoof Vulnerability
References:
References:
- Bug 370555 (CVE-2007-1004) �?? URL bar not always updated when scripts interact wi (Mozilla Foundation)
- Firefox: about:blank is phisher's best friend (Michal Zalewski
)