Secunia Advisory SA12160

Mozilla / Mozilla Firefox "onunload" SSL Certificate Spoofing
Secunia Advisory SA12160
Get alerted and manage the vulnerability life cycle
Release Date 2004-07-26
Last Update 2004-08-05
   
Popularity 37,062 views
Comments 0 comments

Criticality level Moderately criticalModerately critical
Impact Spoofing
Where From remote
Authentication level Available in Customer Area
   
Report reliability Available in Customer Area
Solution Status Vendor Patch
   
Systems affected Available in Customer Area
Approve distribution Available in Customer Area
   
Software:
Mozilla 0.x
Mozilla 1.0
Mozilla 1.1
Mozilla 1.2
Mozilla 1.3
Mozilla 1.4
Mozilla 1.5
Mozilla 1.6
Mozilla 1.7.x
Mozilla Firefox 0.x
Mozilla Thunderbird 0.x

Secunia CVSS Score Available in Customer Area
CVE Reference(s) CVE-2004-0763 CVSS available in Customer Area
  

Description
Emmanouel Kellinis has reported a vulnerability in Mozilla and Mozilla Firefox, allowing malicious sites to abuse SSL certificates of other sites.

It is possible to make the browser load a valid certificate from a trusted website by using a specially crafted "onunload" event. The problem is that Mozilla loads the certificate from a trusted website and shows the "secure padlock" while actually displaying the content of the malicious website.

The URL shown in the address bar correctly reads that of the malicious website.

This has been confirmed using Mozilla Firefox 0.9.2 and Mozilla 1.7.1 on Windows and Mozilla Firefox 0.9.1 on Linux. Other versions may also be affected.

Solution
The vulnerability has been fixed in the following versions:
Further details available in Customer Area

Provided and/or discovered by
Emmanouel Kellinis

Changelog
Further details available in Customer Area

Original Advisory
Emmanouel Kellinis:
http://www.cipher.org.uk/index.php?p=advisories/Certificate_Spoofing_Mozilla_FireFox_25-07-2004.advisory

Mozilla Bug Tracking System:
http://bugzilla.mozilla.org/show_bug.cgi?id=253121

Deep Links
Links available in Customer Area


Do you have additional information related to this advisory?
Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
Subject: Mozilla / Mozilla Firefox "onunload" SSL Certificate Spoofing
 
No posts yet

-

You must be logged in to post a comment.



footer
© 2002-2010 Secunia ApS • Weidekampsgade 14A, DK-2300 Copenhagen S, Denmark • +45 7020 5144 • Contact Us
Terms & Conditions and CopyrightReport vulnerability
CVE logo OTA logo First logo