FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-1834

This CVE name corresponds to:

Entered Topic
2009-06-12 mozilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-1834
Phase Assigned(20090529)

Description

Visual truncation vulnerability in netwerk/dns/src/nsIDNService.cpp in Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 allows remote attackers to spoof the location bar via an IDN with invalid Unicode characters that are displayed as whitespace, as demonstrated by the \u115A through \u115E characters.

References

Source Reference
CONFIRM http://www.mozilla.org/security/announce/2009/mfsa2009-25.html
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=479413
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=503573
DEBIAN DSA-1820
FEDORA FEDORA-2009-6366
FEDORA FEDORA-2009-6411
REDHAT RHSA-2009:1095
SLACKWARE SSA:2009-167-01
SUNALERT 264308
BID 35326
BID 35388
OSVDB 55162
OVAL oval:org.mitre.oval:def:10436
SECUNIA 35331
SECUNIA 35431
SECUNIA 35439
SECUNIA 35468
SECUNIA 35415
VUPEN ADV-2009-1572