CVE-2005-0593: Low severity Mozilla Firefox vulnerability
Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the lock of the previous site, (2) a non-HTTP server that uses SSL, which causes the lock to be displayed when the SSL handshake is completed, or (3) a URL that generates an HTTP 204 error, which updates the icon and location information but does not change the display of the original site.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0593?
CVE-2005-0593 is classified as a moderate severity vulnerability.
How does CVE-2005-0593 affect users?
CVE-2005-0593 allows attackers to potentially spoof the SSL secure site lock icon, misrepresenting the security of a site to users.
What versions are affected by CVE-2005-0593?
CVE-2005-0593 affects Firefox versions prior to 1.0.1 and Mozilla versions before 1.7.6.
How can I fix CVE-2005-0593?
To fix CVE-2005-0593, users should upgrade to Firefox 1.0.1 or Mozilla 1.7.6 or later.
What types of attacks can CVE-2005-0593 facilitate?
CVE-2005-0593 facilitates phishing attacks by misleading users about the security status of web pages.