First published: Mon Jun 01 2009(Updated: )
Mozilla add-on developer Pavel Cvrcek reported that certain invalid unicode characters, when used as part of an IDN, are displayed as whitespace in the location bar. This whitespace could be used to force part of the URL out of view in the location bar. An attacker could use this vulnerability to spoof the location bar and display a misleading URL for their malicious web page.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla SeaMonkey | =1.1.10 | |
Mozilla Firefox | =0.1 | |
Mozilla Firefox | =0.9_rc | |
Mozilla SeaMonkey | =1.0.3 | |
Mozilla Firefox | =0.8 | |
Mozilla Firefox | =2.0.0.12 | |
Mozilla Firefox | =1.5-beta2 | |
Mozilla Firefox | =2.0_.7 | |
Mozilla SeaMonkey | =1.1.8 | |
Mozilla SeaMonkey | <=1.1.16 | |
Mozilla Firefox | =3.0.7 | |
Mozilla Firefox | =1.5.2 | |
Mozilla SeaMonkey | =1.0.1 | |
Mozilla SeaMonkey | =1.1.7 | |
Mozilla Firefox | =3.0.9 | |
Mozilla SeaMonkey | =1.0.6 | |
Mozilla Firefox | =1.5.0.6 | |
Mozilla Firefox | =1.8 | |
Mozilla SeaMonkey | =1.0.9 | |
Mozilla SeaMonkey | =1.1.3 | |
Mozilla Firefox | =2.0.0.2 | |
Mozilla Firefox | =1.5.0.10 | |
Mozilla Firefox | =1.5.0.3 | |
Mozilla SeaMonkey | =1.0 | |
Mozilla Firefox | =3.0.8 | |
Mozilla Firefox | =1.5.0.11 | |
Mozilla Firefox | =1.4.1 | |
Mozilla SeaMonkey | =1.0.99 | |
Mozilla Firefox | =1.5.4 | |
Mozilla SeaMonkey | =1.1.5 | |
Mozilla Firefox | =1.0.2 | |
Mozilla SeaMonkey | =1.0-beta | |
Mozilla Firefox | =3.0.4 | |
Mozilla Firefox | =1.5-beta1 | |
Mozilla SeaMonkey | =1.1-alpha | |
Mozilla Firefox | =2.0_8 | |
Mozilla Firefox | =2.0_.9 | |
Mozilla Firefox | =3.0.5 | |
Mozilla SeaMonkey | =1.0-alpha | |
Mozilla Firefox | =1.5 | |
Mozilla Firefox | =0.9.1 | |
Mozilla Firefox | =1.0.4 | |
Mozilla Firefox | =2.0.0.7 | |
Mozilla Firefox | =1.0.7 | |
Mozilla SeaMonkey | =1.1.12 | |
Mozilla SeaMonkey | =1.1 | |
Mozilla Firefox | =2.0.0.9 | |
Mozilla Firefox | =0.10.1 | |
Mozilla Firefox | =2.0_.1 | |
Mozilla Firefox | =0.9 | |
Mozilla Firefox | =2.0.0.16 | |
Mozilla Firefox | =3.0-beta2 | |
Mozilla Firefox | =1.5.6 | |
Mozilla Firefox | =2.0.0.17 | |
Mozilla Firefox | =0.7 | |
Mozilla Firefox | =2.0.0.15 | |
Mozilla SeaMonkey | =1.0 | |
Mozilla Firefox | =0.2 | |
Mozilla SeaMonkey | =1.0.8 | |
Mozilla Firefox | =0.3 | |
Mozilla SeaMonkey | =1.1.11 | |
Mozilla Firefox | =2.0_.10 | |
Mozilla Firefox | =1.0 | |
Mozilla Firefox | =3.0.3 | |
Mozilla SeaMonkey | =1.1-beta | |
Mozilla SeaMonkey | =1.1.1 | |
Mozilla Firefox | =1.5.0.7 | |
Mozilla Firefox | =2.0 | |
Mozilla Firefox | =1.0.1 | |
Mozilla SeaMonkey | =1.1.5-1.1.10 | |
Mozilla Firefox | =2.0-beta1 | |
Mozilla Firefox | =2.0.0.14 | |
Mozilla Firefox | =0.6 | |
Mozilla Firefox | <=3.0.10 | |
Mozilla Firefox | =0.7.1 | |
Mozilla SeaMonkey | =1.1.15 | |
Mozilla Firefox | =3.0.6 | |
Mozilla Firefox | =1.5.0.8 | |
Mozilla Firefox | =2.0_.5 | |
Mozilla Firefox | =1.0.6 | |
Mozilla Firefox | =2.0.0.3 | |
Mozilla Firefox | =1.5.0.9 | |
Mozilla Firefox | =1.5.0.5 | |
Mozilla Firefox | =1.5.7 | |
Mozilla Firefox | =1.5.0.12 | |
Mozilla Firefox | =2.0.0.6 | |
Mozilla SeaMonkey | =1.1.6 | |
Mozilla Firefox | =3.0 | |
Mozilla Firefox | =2.0.0.11 | |
Mozilla Firefox | =1.5.0.2 | |
Mozilla Firefox | =1.0.3 | |
Mozilla Firefox | =3.0.1 | |
Mozilla Firefox | =2.0.0.4 | |
Mozilla Firefox | =0.5 | |
Mozilla Firefox | =0.6.1 | |
Mozilla Firefox | =1.5.1 | |
Mozilla Firefox | =2.0.0.21 | |
Mozilla Firefox | =0.9.3 | |
Mozilla SeaMonkey | =1.0 | |
Mozilla Firefox | =2.0.0.13 | |
Mozilla Firefox | =2.0.0.18 | |
Mozilla SeaMonkey | =1.0 | |
Mozilla Firefox | =2.0-rc2 | |
Mozilla Firefox | =2.0.0.1 | |
Mozilla Firefox | =3.0.2 | |
Mozilla Firefox | =2.0_.6 | |
Mozilla Firefox | =2.0_.4 | |
Mozilla SeaMonkey | =1.0.4 | |
Mozilla Firefox | =1.5.5 | |
Mozilla Firefox | =0.9.2 | |
Mozilla Firefox | =1.0-preview_release | |
Mozilla Firefox | =2.0-beta_1 | |
Mozilla SeaMonkey | =1.1.9 | |
Mozilla SeaMonkey | =1.1.13 | |
Mozilla Firefox | =2.0.0.20 | |
Mozilla Firefox | =2.0.0.8 | |
Mozilla Firefox | =3.0-beta5 | |
Mozilla Firefox | =0.9-rc | |
Mozilla Firefox | =2.0.0.19 | |
Mozilla Firefox | =1.5.8 | |
Mozilla Firefox | =1.5.3 | |
Mozilla Firefox | =0.4 | |
Mozilla Firefox | =1.5.0.4 | |
Mozilla Firefox | =1.5.0.1 | |
Mozilla Firefox | =0.10 | |
Mozilla Firefox | =1.0.5 | |
Mozilla Firefox | =2.0.0.5 | |
Mozilla Firefox | =2.0.0.10 | |
Mozilla Firefox | =2.0-rc3 | |
Mozilla Firefox | =3.0-alpha | |
Mozilla Firefox | =1.0.6 | |
Mozilla Firefox | =1.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1834 has been rated as a moderate severity vulnerability due to the potential for URL tampering.
To fix CVE-2009-1834, update to the latest version of Mozilla Firefox or SeaMonkey that addresses this vulnerability.
CVE-2009-1834 affects multiple versions of Mozilla Firefox and SeaMonkey.
CVE-2009-1834 can lead to phishing attacks by obscuring parts of a URL in the browser's location bar.
Yes, CVE-2009-1834 can be exploited remotely through crafted URLs to mislead users.