Jump to content

Multiple Browsers Frame Injection Vulnerability


Redhat
 Share

Recommended Posts

Multiple Browsers Frame Injection Vulnerability

Secunia Advisory: SA11978 Print Advisory

Release Date: 2004-07-01

Critical:

Moderately critical

Impact: Spoofing

Where: From remote

Software: Internet Explorer 5.x for Mac

Konqueror 3.x

Mozilla 0.x

Mozilla 1.0

Mozilla 1.1

Mozilla 1.2

Mozilla 1.3

Mozilla 1.4

Mozilla 1.5

Mozilla 1.6

Mozilla Firefox 0.x

Netscape 6.x

Netscape 7.x

Opera 5.x

Opera 6.x

Opera 7.x

Safari 1.x

Choose a product and view comprehensive vulnerability statistics and all Secunia advisories affecting it.

Description:

A 6 year old vulnerability has been discovered in multiple browsers, allowing malicious people to spoof the content of websites.

The problem is that the browsers don't check if a target frame belongs to a website containing a malicious link, which therefore doesn't prevent one browser window from loading content in a named frame in another window.

Successful exploitation allows a malicious website to load arbitrary content in an arbitrary frame in another browser window owned by e.g. a trusted site.

Secunia has constructed a test, which can be used to check if your browser is affected by this issue:

»secunia.com/multiple_browsers_frame_in..

The vulnerability has been confirmed in the following browsers:

* Opera 7.51 for Windows

* Opera 7.50 for Linux

* Mozilla 1.6 for Windows

* Mozilla 1.6 for Linux

* Mozilla Firebird 0.7 for Linux

* Mozilla Firefox 0.8 for Windows

* Netscape 7.1 for Windows

* Internet Explorer for Mac 5.2.3

* Safari 1.2.2

* Konqueror 3.1-15redhat

Other versions may also be affected.

The vulnerability also affects Internet Explorer:

SA11966

Solution:

Do not browse untrusted sites while browsing trusted sites.

The following browsers are not affected:

* Mozilla Firefox 0.9 for Windows

* Mozilla Firefox 0.9.1 for Windows

* Mozilla 1.7 for Windows

* Mozilla 1.7 for Linux

Provided and/or discovered by:

Reported in Mozilla browser by:

Gary McKay

» http://secunia.com/advisories/11978/

Link to comment
Share on other sites

But mozilla 0.x to 1.x are affected, as well as firefox 0.x and IE 6.x and opera 5,6 and 7.x

so that pretty much covers them all! (end users would know about anyways)

Upgrading to Firefox 0.9.1 or Mozilla 1.7 is the main idea to be protected.

But 0.x and 1.x are affected, does this mean the new versions have protected this?

does this affect Linux as well?

Link to comment
Share on other sites

For IE..

Internet Explorer/Tools/Internet Options/Security/Internet Zone/Custom Level....change Navigate sub-frames across different domains to disabled and the exploit doesn't work.

Changed it to "disabled" as well for Trusted Zone in Internet Explorer.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy