Mozilla Firefox homoglyph character spoofing
| mozilla-firefox-homoglyph-spoofing (48974) |
Description:
Mozilla Firefox is vulnerable to spoofing attacks, caused by improper rendering of homoglyph characters in IDN domain names. A remote attacker could exploit this vulnerability using homoglyphs of the / (slash) and ? (question mark) characters to spoof URLs and conduct phishing attacks.
*CVSS:
| Base Score: | 4.3 |
| Access Vector: | Network |
| Access Complexity: | Medium |
| Authentication: | None |
| Confidentiality Impact: | None |
| Integrity Impact: | Partial |
| Availability Impact: | None |
| Temporal Score: | 3 |
| Exploitability: | Unproven |
| Remediation Level: | Official-Fix |
| Report Confidence: | Uncorroborated |
Consequences:
Other
Remedy:
Apply the appropriate patch for your system. See References.
References:
- Moxie Marlinspike Whitepaper: New Tricks For Defeating SSL In Practice.
- Mozilla Web site: IDN-enabled TLDs.
- ASA-2009-152: firefox security update (RHSA-2009-0436)
- ASA-2009-154: seamonkey security update (RHSA-2009-0437)
- BID-33837: Mozilla Firefox International Domain Name Subdomain URI Spoofing Vulnerability
- CVE-2009-0652: The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233. NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.
- DSA-1797: xulrunner -- several vulnerabilities
- DSA-1830: icedove -- several vulnerabilities
- MDVSA-2009:111: firefox
- MDVSA-2009:111-1: firefox
- RHSA-2009-0436: Critical: firefox security update
- RHSA-2009-0437: Critical: seamonkey security update
- SA34096: Mozilla Firefox IDN Spoofing Security Issue
- SUSE-SR:2009:010: SUSE Security Summary Report
- USN-764-1: Firefox and Xulrunner vulnerabilities
- VUPEN/ADV-2009-1125: Mozilla Firefox Memory Corruption and Security Bypass Vulnerabilities
Platforms Affected:
- Canonical Ubuntu 8.04 LTS
- Canonical Ubuntu 8.10
- Debian Debian Linux 5.0
- Mandriva Linux 2009.0 X86_64
- Mandriva Linux 2009.0
- Mandriva Linux 2009.1 X86_64
- Mandriva Linux 2009.1
- Mozilla Firefox 3.0
- Mozilla Firefox 3.0.1
- Mozilla Firefox 3.0.2
- Mozilla Firefox 3.0.3
- Mozilla Firefox 3.0.4
- Mozilla Firefox 3.0.5
- Mozilla Firefox 3.0.6
- RedHat Enterprise Linux 2.1 ES
- RedHat Enterprise Linux 2.1 WS
- RedHat Enterprise Linux 2.1 AS
- RedHat Enterprise Linux 3 ES
- RedHat Enterprise Linux 3 AS
- RedHat Enterprise Linux 3 Desktop
- RedHat Enterprise Linux 3 WS
- RedHat Enterprise Linux 4 Desktop
- RedHat Enterprise Linux 4 WS
- RedHat Enterprise Linux 4 ES
- RedHat Enterprise Linux 4 AS
- RedHat Enterprise Linux 4.7.z AS
- RedHat Enterprise Linux 5
- RedHat Enterprise Linux 5 Client Workstation
- RedHat Enterprise Linux 5 Client
- RedHat Enterprise Linux 5.3.z EUS
- RedHat Enterprise Linux Long Life 5.3
- RedHat Linux Advanced Workstation 2.1 Itanium
- RedHat Red Hat Enterprise Linux 4.7.z ES
Reported:
Feb 19, 2009
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
* According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an "industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response." IBM PROVIDES THE CVSS SCORES "AS IS" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall IBM be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
