FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-0594

This CVE name corresponds to:

Entered Topic
2008-02-22 mozilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-0594
Phase Assigned(20080205)

Description

Mozilla Firefox before 2.0.0.12 does not always display a web forgery warning dialog if the entire contents of a web page are in a DIV tag that uses absolute positioning, which makes it easier for remote attackers to conduct phishing attacks.

References

Source Reference
BUGTRAQ 20080209 rPSA-2008-0051-1 firefox
BUGTRAQ 20080212 FLEA-2008-0001-1 firefox
CONFIRM http://www.mozilla.org/security/announce/2008/mfsa2008-11.html
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=408164
CONFIRM http://wiki.rpath.com/Advisories:rPSA-2008-0051
CONFIRM http://browser.netscape.com/releasenotes/
CONFIRM http://support.novell.com/techcenter/psdb/6251b18e050302ebe7fe74294b55c818.html
DEBIAN DSA-1484
DEBIAN DSA-1485
DEBIAN DSA-1489
DEBIAN DSA-1506
FEDORA FEDORA-2008-1435
FEDORA FEDORA-2008-1535
MANDRIVA MDVSA-2008:048
SUSE SUSE-SA:2008:008
UBUNTU USN-576-1
BID 27683
FRSIRT ADV-2008-0453
FRSIRT ADV-2008-0627
SECTRACK 1019342
SECUNIA 28864
SECUNIA 28865
SECUNIA 28877
SECUNIA 28879
SECUNIA 28924
SECUNIA 28939
SECUNIA 28958
SECUNIA 29086
SECUNIA 29567