CVE-2008-0367
Last modified
CVE-2008-0367 is a vulnerability of currently unknown severity. Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authentication after the Realm text, which might make it easier for remote HTTP servers to conduct phishing and spoofing attacks.. EPSS estimates a 1.81% chance of exploitation in the next 30 days.
Description
Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authentication after the Realm text, which might make it easier for remote HTTP servers to conduct phishing and spoofing attacks.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Mozilla | Firefox | <= 2.0.0.11 | — |
| Mozilla | Firefox | 3.0 | Beta2 |
References
- http://aviv.raffon.net/2008/01/05/FirefoxDialogSpoofingFAQ.aspxThird Party Advisory
- http://www.securityfocus.com/archive/1/485732/100/200/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/485738/100/200/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/27111Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=244273Issue Tracking, Vendor Advisory
- http://aviv.raffon.net/2008/01/05/FirefoxDialogSpoofingFAQ.aspxThird Party Advisory
- http://www.securityfocus.com/archive/1/485732/100/200/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/485738/100/200/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/27111Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=244273Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-0367?
How severe is CVE-2008-0367?
How do I fix CVE-2008-0367?
Are you affected by CVE-2008-0367?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
