First published: Mon Feb 28 2005(Updated: )
Firefox before 1.0.1 and Mozilla before 1.7.6, when displaying the HTTP Authentication dialog, do not change the focus to the tab that generated the prompt, which could facilitate spoofing and phishing attacks.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | =0.8 | |
Firefox | =0.9 | |
Firefox | =0.9-rc | |
Firefox | =0.9.1 | |
Firefox | =0.9.2 | |
Firefox | =0.9.3 | |
Firefox | =0.10 | |
Firefox | =0.10.1 | |
Firefox | =1.0 | |
Mozilla Firefox | =1.3 | |
Mozilla Firefox | =1.4 | |
Mozilla Firefox | =1.4-alpha | |
Mozilla Firefox | =1.4.1 | |
Mozilla Firefox | =1.5 | |
Mozilla Firefox | =1.5-alpha | |
Mozilla Firefox | =1.5-rc1 | |
Mozilla Firefox | =1.5-rc2 | |
Mozilla Firefox | =1.5.1 | |
Mozilla Firefox | =1.6 | |
Mozilla Firefox | =1.6-alpha | |
Mozilla Firefox | =1.6-beta | |
Mozilla Firefox | =1.7 | |
Mozilla Firefox | =1.7-alpha | |
Mozilla Firefox | =1.7-beta | |
Mozilla Firefox | =1.7-rc1 | |
Mozilla Firefox | =1.7-rc2 | |
Mozilla Firefox | =1.7-rc3 | |
Mozilla Firefox | =1.7.1 | |
Mozilla Firefox | =1.7.2 | |
Mozilla Firefox | =1.7.3 | |
Mozilla Firefox | =1.7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0584 is classified as a moderate severity vulnerability due to its potential for facilitating spoofing and phishing attacks.
To mitigate CVE-2005-0584, upgrade to Firefox version 1.0.1 or newer, or Mozilla version 1.7.6 or newer.
CVE-2005-0584 affects Firefox versions prior to 1.0.1 and Mozilla versions prior to 1.7.6.
The implications of CVE-2005-0584 include the risk of users falling victim to phishing attacks due to an unanticipated focus shift when the HTTP Authentication dialog appears.
While CVE-2005-0584 primarily affects outdated versions of browsers, users of legacy systems should remain cautious of such vulnerabilities.