CVE-2008-0367
Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authentication after the Realm text, which might make it easier for remote HTTP servers to conduct phishing…
Does this matter?
Lower severity and a low EPSS score (1.81%). Track it; it rarely justifies an emergency change on its own.
Description
Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authentication after the Realm text, which might make it easier for remote HTTP servers to conduct phishing and spoofing attacks.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.81% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- mozilla/firefox
- Source
- cve@mitre.org
References
- http://aviv.raffon.net/2008/01/02/YetAnotherDialogSpoofingFirefoxBasicAuthentication.aspxThird Party Advisory
- http://aviv.raffon.net/2008/01/05/FirefoxDialogSpoofingFAQ.aspxThird Party Advisory
- http://blog.mozilla.com/security/2008/01/04/basicauth-dialog-realm-value-spoofing/Vendor Advisory
- http://www.securityfocus.com/archive/1/485732/100/200/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/485738/100/200/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/27111Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=244273Issue Tracking, Vendor Advisory
- http://aviv.raffon.net/2008/01/02/YetAnotherDialogSpoofingFirefoxBasicAuthentication.aspxThird Party Advisory
- http://aviv.raffon.net/2008/01/05/FirefoxDialogSpoofingFAQ.aspxThird Party Advisory
- http://blog.mozilla.com/security/2008/01/04/basicauth-dialog-realm-value-spoofing/Vendor Advisory
- http://www.securityfocus.com/archive/1/485732/100/200/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/485738/100/200/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/27111Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=244273Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.