Mozilla Firefox JavaScript 'Prompted Message' Spoofing Vulnerability
BID:37230
Info
Mozilla Firefox JavaScript 'Prompted Message' Spoofing Vulnerability
| Bugtraq ID: | 37230 |
| Class: | Race Condition Error |
| CVE: |
CVE-2009-4129 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 07 2009 12:00AM |
| Updated: | Dec 15 2009 03:23PM |
| Credit: | Topsec |
| Vulnerable: |
Mozilla Firefox 3.5.5 Mozilla Firefox 3.5.4 Mozilla Firefox 3.5.3 Mozilla Firefox 3.5.2 Mozilla Firefox 3.5.1 Mozilla Firefox 3.5 Mozilla Firefox 3.0.15 Mozilla Firefox 3.0.14 Mozilla Firefox 3.0.13 Mozilla Firefox 3.0.12 Mozilla Firefox 3.0.11 Mozilla Firefox 3.0.10 Mozilla Firefox 3.0.9 Mozilla Firefox 3.0.8 Mozilla Firefox 3.0.7 Beta Mozilla Firefox 3.0.7 Mozilla Firefox 3.0.6 Mozilla Firefox 3.0.5 Mozilla Firefox 3.0.4 Mozilla Firefox 3.0.3 Mozilla Firefox 3.0.2 Mozilla Firefox 3.0.1 Mozilla Firefox 3.1 Beta 3 Mozilla Firefox 3.1 Beta 2 Mozilla Firefox 3.1 Beta 1 Mozilla Firefox 3.0 Beta 5 Mozilla Firefox 3.0 |
| Not Vulnerable: | |
Discussion
Mozilla Firefox JavaScript 'Prompted Message' Spoofing Vulnerability
Mozilla Firefox is affected by a spoofing vulnerability.
An attacker may leverage this issue to present a JavaScript 'prompted message' generated by a malicious domain such that it appears above a window for a targeted, legitimate domain. This may lead to a false sense of trust because the victim may be presented with a URI of a seemingly trusted site while interacting with the attacker's malicious site.
Mozilla Firefox is affected by a spoofing vulnerability.
An attacker may leverage this issue to present a JavaScript 'prompted message' generated by a malicious domain such that it appears above a window for a targeted, legitimate domain. This may lead to a false sense of trust because the victim may be presented with a URI of a seemingly trusted site while interacting with the attacker's malicious site.
Exploit / POC
Mozilla Firefox JavaScript 'Prompted Message' Spoofing Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web document.
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web document.
Solution / Fix
Mozilla Firefox JavaScript 'Prompted Message' Spoofing Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Mozilla Firefox JavaScript 'Prompted Message' Spoofing Vulnerability
References:
References:
- Mozilla Homepage (Mozilla Foundation)
- Mozilla Firefox JavaScript Prompt Spoofing Weakness (tcphttp
)