Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Mozilla Browser Non-FQDN SSL Certificate Spoofing Vulnerability

Mozilla browser is reportedly vulnerable to an SSL certificate spoofing vulnerability in the 'cert_TestHostName()' function. This issue is due to a design error that fails to properly validate certified host names.

This issue would allow an attacker to spoof a trusted certificate from a third party site, facilitating phishing style attacks by luring an unsuspecting user to enter information on what is apparently a trusted site.







 

Privacy Statement
Copyright 2008, SecurityFocus