Mozilla Seamonkey NTLM Implementation Flaw Lets Remote Users Conduct Authentication Reflection Attacks
|
|
SecurityTracker Alert ID: 1023341 |
|
SecurityTracker URL: http://securitytracker.com/id/1023341
|
|
CVE Reference:
CVE-2009-3983
(Links to External Site)
|
Date: Dec 16 2009
|
Impact:
Disclosure of authentication information
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 2.0
|
Description:
A vulnerability was reported in Mozilla Seamonkey. A remote user can conduct authentication reflection attacks.
A remote user can create specially crafted HTML that, when loaded by the target user, will cause the target user's browser to forward NTLM authenticated requests to another application.
Takehiro Takahashi of the IBM X-Force reported this vulnerability.
|
Impact:
A remote user can create HTML that, when loaded by the target user, will cause the target user's browser to forward NTLM authenticated requests to another application.
|
Solution:
The vendor has issued a fix (2.0.1).
The vendor's advisory is available at:
http://www.mozilla.org/security/announce/2009/mfsa2009-68.html
|
Vendor URL: www.mozilla.org/security/announce/2009/mfsa2009-68.html (Links to External Site)
|
Cause:
Access control error
|
Underlying OS:
Linux (Any), UNIX (Any), Windows (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Wed, 16 Dec 2009 05:11:13 +0000
Subject: Mozilla Seamonkey
|
http://www.mozilla.org/security/announce/2009/mfsa2009-68.html
CVE-2009-3983
|
|