First published: Mon Jun 11 2007(Updated: )
Visual truncation vulnerability in Mozilla 1.7.12 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a long hostname, which is truncated after a certain number of characters, as demonstrated by a phishing attack using HTTP Basic Authentication.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | =1.7.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3144 has a medium severity rating, as it allows for visual spoofing that can lead to phishing attacks.
To mitigate CVE-2007-3144, consider upgrading to a later version of Mozilla that does not exhibit this vulnerability.
CVE-2007-3144 specifically affects users of Mozilla version 1.7.12.
CVE-2007-3144 enables remote attackers to spoof the address bar, potentially facilitating phishing attacks.
CVE-2007-3144 was reported in 2007, highlighting vulnerabilities in older versions of the Mozilla browser.