Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 81113 - net-www/mozilla + mozilla-firefox: IDN Spoofing Security Issue (2005-0233)
Summary: net-www/mozilla + mozilla-firefox: IDN Spoofing Security Issue (2005-0233)
Status: RESOLVED DUPLICATE of bug 83267
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High minor (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/14163/
Whiteboard: A4 [upstream] koon
Keywords:
Depends on:
Blocks:
 
Reported: 2005-02-07 06:39 UTC by Jean-François Brunette (RETIRED)
Modified: 2005-07-17 13:06 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jean-François Brunette (RETIRED) gentoo-dev 2005-02-07 06:39:16 UTC
Description:
Eric Johanson has reported a security issue in Mozilla / Firefox / Camino, which can be exploited by a malicious web site to spoof the URL displayed in the address bar, SSL certificate, and status bar.

The problem is caused due to an unintended result of the IDN (International Domain Name) implementation, which allows using international characters in domain names.

This can be exploited by registering domain names with certain international characters that resembles other commonly used characters, thereby causing the user to believe they are on a trusted site.

Secunia has constructed a test, which can be used to check if your browser is affected by this issue:
http://secunia.com/multiple_browsers_idn_spoofing_test/

The issue has been confirmed in Mozilla 1.7.5 and Firefox 1.0. Other versions may also be affected.

Solution:
Disable IDN support by setting network.enableIDN to "false".

Don't follow links from untrusted sources.

Manually type the URL in the address bar.
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-02-07 06:47:47 UTC
Confirmed with Firefox 1.0

Mozilla please advise.
Comment 2 Thierry Carrez (RETIRED) gentoo-dev 2005-02-07 09:05:12 UTC
We'll have to wait for Mozilla to issue new versions. I didn't find any open bug (yet) on Mozilla bugzie.

Note that the "disable IDN" workaround seems to be buggy: 
http://it.slashdot.org/comments.pl?sid=138568&cid=11596841
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-02-08 09:30:44 UTC
https://bugzilla.mozilla.org/show_bug.cgi?id=279099
Comment 4 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-02-08 09:31:21 UTC
CAN-2005-0238 for Epiphany
Comment 5 Olivier Crete (RETIRED) gentoo-dev 2005-02-24 19:54:42 UTC
firefox 1.0.1 with this stuff fixed is out..
Comment 6 Thierry Carrez (RETIRED) gentoo-dev 2005-02-25 08:32:39 UTC
Replaced by metabug 83267

*** This bug has been marked as a duplicate of 83267 ***