1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Netscape Java Tab Spoofing Vulnerability-Mac OSX

Discussion in 'Firefox, Thunderbird & SeaMonkey' started by Ramona, 2004/08/27.

Thread Status:
Not open for further replies.
  1. 2004/08/27
    Ramona

    Ramona Geek Member Alumni Thread Starter

    Joined:
    2001/12/31
    Messages:
    7,481
    Likes Received:
    2
    Secunia Security Advisories reports this vulnerability today:

    SECUNIA ADVISORY ID:
    SA12392

    VERIFY ADVISORY:
    http://secunia.com/advisories/12392/

    CRITICAL:
    Less critical

    IMPACT:
    Spoofing

    WHERE:
    From remote

    OPERATING SYSTEM:
    Apple Macintosh OS X
    http://secunia.com/product/96/

    SOFTWARE:
    Netscape 7.x
    http://secunia.com/product/85/

    DESCRIPTION:
    J. Courcoul has discovered a vulnerability in Netscape, which can be
    exploited by malicious people to conduct phishing attacks.

    The problem is caused due to errors in the displaying of Java applets
    in a window when multiple tabs are used. This can be exploited to
    spoof the content of a HTML document from another HTML document being
    in a different tab.

    The vulnerability has been confirmed in Netscape 7.2 on Mac OS X
    10.3.5.

    SOLUTION:
    Open untrusted sites in separate windows.

    PROVIDED AND/OR DISCOVERED BY:
    J. Courcoul
     
  2. 2004/08/27
    Antony

    Antony Inactive

    Joined:
    2002/01/01
    Messages:
    405
    Likes Received:
    0
    I tested this vulnerability. I can confirm it exists in Netscape 7.2 (for Mac OS X 10.3.5) and Mozilla 1.7 (for Mac OS X).

    The good news is this vulnerability does not exist in Camino 0.8.1 or Safari 1.2.3.
     

  3. to hide this advert.

  4. 2004/08/27
    Ramona

    Ramona Geek Member Alumni Thread Starter

    Joined:
    2001/12/31
    Messages:
    7,481
    Likes Received:
    2
    Antony,

    Thanks very much for the feedback!

    Ramona
     
  5. 2004/08/28
    Antony

    Antony Inactive

    Joined:
    2002/01/01
    Messages:
    405
    Likes Received:
    0
    I tested more, and I think it might be useful to list the vulnerable browsers.

    Netscape 7.2 for OS X (under both 'Panther' 10.3.5 and 'Jaguar' 10.2.8) exhibits vulnerability.
    Mozilla 1.7 for OS X (under both Panther and Jaguar) exhibits vulnerability
    Firefox 0.9.3 for OS X (under both Panther and Jaguar) exhibits vulnerability.

    Both Macs have latest OS X Security Update and Java update installed.

    Safe browsers:
    Safari 1.2.3 (Panther), Safari 1.0.3 (Jaguar), Camino 0.8.1
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.