CVE-2005-2395
published 2005-07-27CVE-2005-2395: Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause…
PriorityP419medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.38%
82.2th percentile
Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if an encrypted channel is available.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vw3w-fr62-q869: Mozilla Firefox 1
ghsa_unreviewed·2022-05-01
CVE-2005-2395 [MEDIUM] GHSA-vw3w-fr62-q869: Mozilla Firefox 1
Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if an encrypted channel is available.
Debian
CVE-2005-2395: firefox - Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest...
vendor_debian·2005·CVSS 5.0
CVE-2005-2395 [MEDIUM] CVE-2005-2395: firefox - Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest...
Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if an encrypted channel is available.
Scope: local
sid: open
Red Hat
firefox: Does not choose the challenge with the strongest authentication scheme available as required by RFC2617
vendor_redhat·2004-01-17·CVSS 5.0
CVE-2005-2395 [MEDIUM] firefox: Does not choose the challenge with the strongest authentication scheme available as required by RFC2617
firefox: Does not choose the challenge with the strongest authentication scheme available as required by RFC2617
Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if an encrypted channel is available.
Package: firefox (Red Hat Enterprise Linux 5) - Affected
Package: firefox (Red Hat Enterprise Linux 6) - Affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-2395 firefox: Does not choose the challenge with the strongest authentication scheme available as required by RFC2617
bugzilla·2012-12-14·CVSS 5.0
CVE-2005-2395 [MEDIUM] CVE-2005-2395 firefox: Does not choose the challenge with the strongest authentication scheme available as required by RFC2617
CVE-2005-2395 firefox: Does not choose the challenge with the strongest authentication scheme available as required by RFC2617
Common Vulnerabilities and Exposures assigned an identifier CVE-2005-2395 to the following vulnerability:
Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if an encrypted channel is available.
References:
[1] http://www.securityfocus.com/archive/1/405666
[2] https://bugzilla.mozilla.org/show_bug.cgi?id=281851
[3] http://www.securiteam.com/securitynews/5PP0L00GUQ.html
[4] http://www.securityfocus.com/bid/14325
[5] http://www.osvdb.org/19002
[6] http://securityreason.com/securityalert/8
[7] http://xforce.iss.net/xforce/
Bugzilla
CVE-2005-2395 Wrong scheme used when server offers both Basic and Digest auth [rfc2617 obsoletes rfc2068]
bugzilla·2005-02-10·CVSS 5.0
CVE-2005-2395 [MEDIUM] CVE-2005-2395 Wrong scheme used when server offers both Basic and Digest auth [rfc2617 obsoletes rfc2068]
CVE-2005-2395 Wrong scheme used when server offers both Basic and Digest auth [rfc2617 obsoletes rfc2068]
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.5) Gecko/20041107 Firefox/1.0
Build Identifier: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.5) Gecko/20041107 Firefox/1.0
When connecting to a web server that offers both HTTP Basic authentication and
HTTP Digest authentication, Firefox selects to perform Basic authentication
rather then the more secure Digest authentication scheme. This behavior is in
contrast to RFC 2617 requirement, which describes HTTP authentication:
4.6 Weakness Created by Multiple Authentication Schemes
An HTTP/1.1 server may return multiple challenges with a 401
(Authenticate) response, and each challenge may use a different
auth-s
http://securityreason.com/securityalert/8http://www.osvdb.org/19002http://www.securiteam.com/securitynews/5PP0L00GUQ.htmlhttp://www.securityfocus.com/archive/1/405666http://www.securityfocus.com/bid/14325https://bugzilla.mozilla.org/show_bug.cgi?id=281851https://exchange.xforce.ibmcloud.com/vulnerabilities/22272http://securityreason.com/securityalert/8http://www.osvdb.org/19002http://www.securiteam.com/securitynews/5PP0L00GUQ.htmlhttp://www.securityfocus.com/archive/1/405666http://www.securityfocus.com/bid/14325https://bugzilla.mozilla.org/show_bug.cgi?id=281851https://exchange.xforce.ibmcloud.com/vulnerabilities/22272
2005-07-27
Published