Firefox "wyciwyg://" Handler Vulnerability

You are here:  SillyDog701 > Message Centre > Firefox, SeaMonkey and Netscape > [sdt=13615]
SillyDog701 Forums
Author Message
Ramona
Moderator


Joined: 19 Jun 2002
Posts: 2360
Location: Midwest USA
10 Jul, 2007 2:35 pm Firefox "wyciwyg://" Handler Vulnerability [sdp=86037]  

Firefox "wyciwyg://" Handler Vulnerability

Secunia Advisory: SA25990
Release Date: 2007-07-10

Critical: Less critical
Impact: Spoofing

Exposure of sensitive information
Where: From remote
Solution Status: Unpatched

Software: Mozilla Firefox 2.0.x

Description:
Michal Zalewski has discovered a vulnerability in Mozilla Firefox, which can be exploited by malicious people to disclose sensitive information and conduct spoofing attacks.

The vulnerability is caused due to an error in the handling of the "wyciwyg://" URI handler. This can be exploited to access or spoof contents from a previously cached web site e.g. via HTTP 302 redirects when a user visits a malicious web page.

The vulnerability is confirmed in version 2.0.0.4. Other versions may also be affected.

Solution:
Do not browse untrusted web sites.

Provided and/or discovered by:
Michal Zalewski

Original Advisory:
http://lcamtuf.coredump.cx/ffcache/

UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.4) Gecko/20070515 Firefox/2.0.0.4

Back to top profile
Antony
Site Admin


Joined: 18 Jun 2002
Posts: 11914
19 Jul, 2007 1:00 am [sdp=86198]  

This vulnerability is addressed in Firefox 2.0.0.5.

Mozilla Foundation Security Advisory 2007-24

UserAgent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en-US; rv:1.8.1.4) Gecko/20070515 Firefox/2.0.0.4

Back to top profile website
Display posts from previous:   
Reply to topic    Forum Index > Firefox, SeaMonkey and Netscape All times are CST (GMT -6)
page 1 of 1
To add your questions, comments, and for more features and more, please join SillyDog701 Message Centre. It's free! This is SillyDog 701 Message Centre (SD701 Forums).
Sportster parts - shop online for harley davidson parts & accessories at 20% discount.
Buy Text Links - buy and/or sell text link ads.

Free Single of the Week iTunes .Mac

*Search | FAQ | Rules and Policies | MozInfo701 - Mozilla Information Centre | SD701 Open Directory | Message Board Map | download Netscape