Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Mozilla SSL Redirect Spoofing Vulnerability

It is reported that Mozilla, and products derived from Mozilla are susceptible to an SSL redirect spoofing vulnerability.

By exploiting this vulnerability, an attacker can ensure that the victims browser contains the SSL lock icon, and will display the SSL certificate information of a legitimate site when the lock is clicked on.

This vulnerability may aid in Phishing style attacks.

Mozilla prior to 1.7, Mozilla Firebird 0.7, Mozilla Firefox prior to 0.9, and Mozilla Thunderbird prior to 0.7 are all reported vulnerable.







 

Privacy Statement
Copyright 2008, SecurityFocus