Mozilla, Firebird, and Firefox cached password in plain text
| mozilla-plaintext-password (17018) |
Description:
Mozilla could allow a remote attacker to cause a cached password be sent in plain text, caused by improper validation of cached passwords for SSL (Secure Socket Layer) sessions in the Web browsers. By allowing a user to enter their password using a trusted site, a remote attacker could then spoof the DNS (Domain Name Server) for a non-ssl version to cause the Web browser to send the cached password in plain text.
Consequences:
Obtain Information
Remedy:
For Mozilla:
Upgrade to the latest version of Mozilla (1.7.2 or later), available from the Mozilla Web site. See References.
For Mandrake Linux:
Upgrade to the latest mozilla package, as listed below. Refer to Mandrakesoft Security Advisory MDKSA-2004:082 for more information. See References.
Mandrake Linux 9.2: 1.4-13.3.92mdk or later
Mandrake Linux 10.0: 1.6-12.1.100mdk or later
For other distributions:
Contact your vendor for upgrade or patch information.
References:
- Mozilla Bugzilla Bug 226278: Password cache for http auth should remember if the site was secure.
- Mozilla Web site: The Latest From Mozilla.
- CVE-2004-0779: The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to be sent in cleartext to a spoofed site.
Platforms Affected:
- FirebirdSQL Firebird 0.7
- MandrakeSoft Mandrake Linux 10.0
- MandrakeSoft Mandrake Linux 9.2
- Mozilla Firefox 0.8
- Mozilla Mozilla 1.6
Reported:
Jul 27, 2004
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
