Mozilla Firefox URL Bug Lets Remote Users Spoof HTTP Referer Values in Certain Cases
|
|
SecurityTracker Alert ID: 1019703
|
|
SecurityTracker URL: http://securitytracker.com/id?1019703
|
|
CVE Reference: CVE-2008-1238
(Links to External Site)
|
Date: Mar 26 2008
|
Impact: Modification of user information
|
Fix Available: Yes
Exploit Included: Yes
Vendor Confirmed: Yes
|
Advisory: Mozilla Foundation Security Advisory
|
Version(s): prior to 2.0.0.13
|
Description: A vulnerability was reported in Mozilla Firefox. A remote user can spoof the HTTP Referer value in certain cases.
When a request is sent to a URL with Basic Authentication credentials and an empty username value, the browser removes characters
from the hostname in the HTTP Referer field. If a target web site relies on the value for security purposes, the remote user may
be able to bypass security controls.
Gregory Fleischer reported this vulnerability. RSnake reported the original concept.
|
Impact: A remote user can spoof the HTTP Referer value to potentially bypass security controls on the target web site.
|
Solution: The vendor has issued a fix (2.0.0.13).
The vendor's advisory is available at:
http://www.mozilla.org/security/announce/2008/mfsa2008-16.html
|
Vendor URL: www.mozilla.org/security/announce/2008/mfsa2008-16.html (Links to External Site)
|
Cause: State error
|
Underlying OS: Linux (Any), UNIX (Any), Windows (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Wed, 26 Mar 2008 00:10:50 -0500
Subject: Mozilla Firefox
|
http://www.mozilla.org/security/announce/2008/mfsa2008-16.html
http://sla.ckers.org/forum/read.php?10,20033
CVE-2008-1238
|
|