Уязвимость спуфинга URL и фишинговых атак из-за недопустимых символов в черном списке IDN в Mozilla Firefox, Thunderbird и SeaMonkey
Описание
Отсутствие символов построения рамок в черном списке IDN (Internationalized Domain Names) в Mozilla Firefox версии 3.0.6 и других версиях до 3.0.9, Thunderbird до версии 2.0.0.21 и SeaMonkey до версии 1.1.15 позволяет злоумышленникам проводить спуфинг URL и фишинговые атаки. Это достигается за счет использования омоглифов символов / (слэш) и ? (вопросительный знак) в поддомене на домене с .cn. Эта уязвимость отличается от уязвимости CVE-2005-0233. Некоторые сторонние источники утверждают, что версия 3.0.6 не затронута, но возможно, более старые версии подвержены этой проблеме.
Затронутые версии ПО
- Mozilla Firefox версии 3.0.6 и более старые версии до 3.0.9
- Thunderbird версии до 2.0.0.21
- SeaMonkey версии до 1.1.15
Тип уязвимости
- Спуфинг URL
- Фишинговые атаки
Ссылки
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Одно из
EPSS
5.8 Medium
CVSS2
Дефекты
Связанные уязвимости
The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233. NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.
The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233. NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.
The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox ...
The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233. NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.
EPSS
5.8 Medium
CVSS2