|
Mozilla / Mozilla Firefox User Interface Spoofing Vulnerability
|
|
Secunia Advisory:
|
SA12188
|
|
|
Release Date:
|
2004-07-30
|
|
Last Update:
|
2004-12-20
|
|
Popularity:
|
62,512 views
|
|
|
Critical:
|
 Moderately critical
|
|
Impact:
|
Spoofing
|
|
Where:
|
From remote
|
|
Solution Status:
|
Partial Fix
|
|
| Software: | Mozilla 0.x Mozilla 1.0 Mozilla 1.1 Mozilla 1.2 Mozilla 1.3 Mozilla 1.4 Mozilla 1.5 Mozilla 1.6 Mozilla 1.7.x Mozilla Firefox 0.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2004-0764
|
|
Description: A vulnerability has been reported in Mozilla and Mozilla Firefox, allowing malicious websites to spoof the user interface.
The problem is that Mozilla and Mozilla Firefox don't restrict websites from including arbitrary, remote XUL (XML User Interface Language) files. This can be exploited to "hijack" most of the user interface (including tool bars, SSL certificate dialogs, address bar and more), thereby controlling almost anything the user sees.
The Mozilla user interface is built using XUL files.
A PoC (Proof of Concept) exploit for Mozilla Firefox has been published. The PoC spoofs a SSL secured PayPal website.
This has been confirmed using Mozilla 1.7 for Linux, Mozilla Firefox 0.9.1 for Linux, Mozilla 1.7.1 for Windows and Mozilla Firefox 0.9.2 for Windows. Prior versions may also be affected.
NOTE: This issue appears to be the same as Mozilla Bug 244965.
Solution: The vulnerability has been partly fixed in Mozilla Firefox 1.0PR so that the status bar always is visible. A final solution will be added in an upcoming version.
Do not follow links from untrusted sites.
Provided and/or discovered by: Reported in Mozilla Firefox by:
Jeff Smith (also created a PoC)
Reported in Mozilla by:
James Ross
Changelog: 2004-07-30: Added an additional Mozilla Bug reference.
2004-08-02: Updated credits section.
2004-08-03: Added CVE reference.
2004-09-17: Updated "Solution" section. Added Bugzilla reference.
2004-12-20: Added link to US-CERT vulnerability note.
Original Advisory: Original Advisory and Proof of Concept:
http://www.nd.edu/~jsmith30/xul/test/spoof.html
Other References: XUL Documentation:
http://www.xulplanet.com/
Mozilla Bug reference:
http://bugzilla.mozilla.org/show_bug.cgi?id=22183
Mozilla Bug reference:
http://bugzilla.mozilla.org/show_bug.cgi?id=244965
Mozilla Bug reference:
http://bugzilla.mozilla.org/show_bug.cgi?id=252198
US-CERT VU#262350:
http://www.kb.cert.org/vuls/id/262350
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|