Jump to content

Revenge of the Frame Injection Spoofing Flaw


Recommended Posts

Secunia has issued a security advisory about a frame injection vulnerability in various Mozilla browsers. The flaw allows a malicious website in one window to load content into a frame that's part of a different site in another window. While this does not present much risk by itself, it could be used as part of a spoofing attack. The Mozilla Foundation is aware of the issue and a fix has been checked in to the trunk and the Mozilla 1.7 and Aviary (Mozilla Firefox 1.0.x and Mozilla Thunderbird 1.0.x) branches.

The frame injection vulnerability first appeared in 1998, when it was found to affect many different browsers, and has cropped up several times over the last few years due to various regressions (changes unintentionally bringing the bug back). Firefox 1.0.3 and 1.0.4 are affected, as are versions 1.7.7 and 1.7.8 of the Mozilla Application Suite. Secunia has a separate frame injection security advisory for Camino 0.8.4. As this is a regression, Firefox 1.0.2, Mozilla 1.7.6 and Camino 0.8.3 are not affected.

More technical details about the vulnerability and how the regression occurred can be found in bug 296850 (no unnecessary comments please).

Slashdot has an article about the return of the spoofing flaw with many user comments. GAThrawn wrote in to tell us that The Register also has a report about the frame injection vulnerability.

From MozillaZine

Link to comment
Share on other sites

  • 2 weeks later...

Firefox 1.0.5 test builds available

[Edited (with Internet Explorer) to remove links to the latest builds; I am unable to run the newly installed 1.0.5 test build (Windows).]

[Edited (with Firefox 1.0.5) to add that the Windows installer from the download link above works correctly.]

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy