CVE-2005-2395: Medium severity Mozilla Firefox vulnerability
Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if an encrypted channel is available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2395?
CVE-2005-2395 has a medium severity rating due to the potential for plaintext credential transmission.
How do I fix CVE-2005-2395?
The best fix for CVE-2005-2395 is to upgrade to a more recent and supported version of Mozilla Firefox.
Which versions of Mozilla Firefox are affected by CVE-2005-2395?
CVE-2005-2395 affects Mozilla Firefox versions 1.0.4 and 1.0.5.
What risks are associated with CVE-2005-2395?
The primary risk associated with CVE-2005-2395 is the possibility of user credentials being sent in plaintext over potentially insecure connections.
What is the cause of CVE-2005-2395?
CVE-2005-2395 is caused by Mozilla Firefox not selecting the strongest available authentication scheme as specified by RFC2617.