Mozilla / Mozilla Firefox / Camino Frame Injection Vulnerability

Tuesday, June 07 2005 @ 10:19 AM EDT

A seven year old vulnerability has been re-introduced in Mozilla and Firefox, which can be exploited by malicious people to spoof the contents of web sites.

Secunia has constructed a test, which can be used to check if your browser is affected:
http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/

The vulnerability has been confirmed in Firefox 1.0.4, Mozilla 1.7.8 and has been confirmed in Camino 0.8.4, but does not affect version 0.8.3. Other versions may also be affected.

SOFTWARE:
Mozilla Firefox 1.x
Mozilla 1.7.x
Camino 0.x

SOLUTION:
Do not browse untrusted web sites while browsing trusted sites.

VERIFY ADVISORY:
http://secunia.com/advisories/15601/
http://secunia.com/advisories/15602/

Secunia Security Advisories

0 comments



http://community.securityteam.us/article.php/20050607101904889