Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2004-0765

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2004-0765
Last Modified 21 Aug 2010 12:21:14
Published 18 Aug 2004 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2004-0765

Summary

The cert_TestHostName function in Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, only checks the hostname portion of a certificate when the hostname portion of the URI is not a fully qualified domain name (FQDN), which allows remote attackers to spoof trusted certificates.

Vulnerable Systems

Application

  • Mozilla 1.7

  • Mozilla Firefox 0.9

  • Mozilla Thunderbird 0.7


References

REDHAT - RHSA-2004:421

CONFIRM - http://bugzilla.mozilla.org/show_bug.cgi?id=234058

XF - mozilla-certtesthostname-certificate-spoof(16868)

SUSE - SUSE-SA:2004:036

CONFIRM - http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7

FEDORA - FLSA:2089


Last Updated: 27 May 2016 10:38:44