Redhat Posted July 8, 2004 Report Share Posted July 8, 2004 Multiple Browsers Frame Injection VulnerabilitySecunia Advisory: SA11978 Print AdvisoryRelease Date: 2004-07-01Critical:Moderately criticalImpact: SpoofingWhere: From remoteSoftware: Internet Explorer 5.x for MacKonqueror 3.xMozilla 0.xMozilla 1.0Mozilla 1.1Mozilla 1.2Mozilla 1.3Mozilla 1.4Mozilla 1.5Mozilla 1.6Mozilla Firefox 0.xNetscape 6.xNetscape 7.xOpera 5.xOpera 6.xOpera 7.xSafari 1.xChoose a product and view comprehensive vulnerability statistics and all Secunia advisories affecting it.Description:A 6 year old vulnerability has been discovered in multiple browsers, allowing malicious people to spoof the content of websites.The problem is that the browsers don't check if a target frame belongs to a website containing a malicious link, which therefore doesn't prevent one browser window from loading content in a named frame in another window.Successful exploitation allows a malicious website to load arbitrary content in an arbitrary frame in another browser window owned by e.g. a trusted site.Secunia has constructed a test, which can be used to check if your browser is affected by this issue:»secunia.com/multiple_browsers_frame_in..The vulnerability has been confirmed in the following browsers:* Opera 7.51 for Windows* Opera 7.50 for Linux* Mozilla 1.6 for Windows* Mozilla 1.6 for Linux* Mozilla Firebird 0.7 for Linux* Mozilla Firefox 0.8 for Windows* Netscape 7.1 for Windows* Internet Explorer for Mac 5.2.3* Safari 1.2.2* Konqueror 3.1-15redhatOther versions may also be affected.The vulnerability also affects Internet Explorer:SA11966Solution:Do not browse untrusted sites while browsing trusted sites.The following browsers are not affected:* Mozilla Firefox 0.9 for Windows* Mozilla Firefox 0.9.1 for Windows* Mozilla 1.7 for Windows* Mozilla 1.7 for LinuxProvided and/or discovered by:Reported in Mozilla browser by:Gary McKay» http://secunia.com/advisories/11978/ Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted July 8, 2004 Report Share Posted July 8, 2004 :o O.K. so I'm affected. What can I do? Is there a fix? I didn't see any links there. From what I gather, we are just supposed to "be careful"? This could be a big one as far as end-users go. How would they know the difference if it was spoofed? Quote Link to comment Share on other sites More sharing options...
Redhat Posted July 8, 2004 Author Report Share Posted July 8, 2004 I don't think there is a fix but you can read the thread at another forum i'm active at : http://www.dslreports.com/forum/remark,10668711~mode=flatUpgrading to Firefox 0.9.1 or Mozilla 1.7 is the main idea to be protected.edit : spelling. Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted July 8, 2004 Report Share Posted July 8, 2004 But mozilla 0.x to 1.x are affected, as well as firefox 0.x and IE 6.x and opera 5,6 and 7.xso that pretty much covers them all! (end users would know about anyways)Upgrading to Firefox 0.9.1 or Mozilla 1.7 is the main idea to be protected.But 0.x and 1.x are affected, does this mean the new versions have protected this?does this affect Linux as well? Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted July 8, 2004 Report Share Posted July 8, 2004 sorry, read the post from other site.Thanks for the heads up redhat!! Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted July 8, 2004 Report Share Posted July 8, 2004 Internet Explorer 5.X is affected as well. Not that many people use it now-a-days :) Quote Link to comment Share on other sites More sharing options...
Redhat Posted July 8, 2004 Author Report Share Posted July 8, 2004 For IE..Internet Explorer/Tools/Internet Options/Security/Internet Zone/Custom Level....change Navigate sub-frames across different domains to disabled and the exploit doesn't work.Changed it to "disabled" as well for Trusted Zone in Internet Explorer. Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted July 8, 2004 Report Share Posted July 8, 2004 Thanks again redhat :DHow about firefox? Quote Link to comment Share on other sites More sharing options...
Redhat Posted July 8, 2004 Author Report Share Posted July 8, 2004 Just upgrade to 0.9.1 : http://www.mozilla.org Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.