CVE-2009-0652
published 2009-02-20CVE-2009-0652: The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before…
PriorityP423medium5.8CVSS 2.0
AVNACMAuNCNIPAP
EPSS
1.50%
71.3th percentile
The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233. NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.
Affected
86 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 3.0.6 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
vendor_redhat7.5HIGH
vendor_ubuntu5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox and Xulrunner vulnerabilities
vendor_ubuntu·2009-04-23·CVSS 5.8
CVE-2009-1302 [MEDIUM] Firefox and Xulrunner vulnerabilities
Title: Firefox and Xulrunner vulnerabilities
Summary: Firefox and Xulrunner vulnerabilities
Several flaws were discovered in the browser engine. If a user were tricked
into viewing a malicious website, a remote attacker could cause a denial of
service or possibly execute arbitrary code with the privileges of the user
invoking the program. (CVE-2009-1302, CVE-2009-1303, CVE-2009-1304,
CVE-2009-1305)
It was discovered that Firefox displayed certain Unicode characters which
could be visually confused with punctuation in valid web addresses in the
location bar. An attacker could exploit this to spoof the location bar,
such as in a phishing attack. (CVE-2009-0652)
Several flaws were discovered in the way Firefox processed malformed URI
schemes. If a user were tricked into viewing a maliciou
Red Hat
firefox: does not properly prevent the literal rendering of homoglyph characters in IDN domain names (spoof URLs and conduct phishing attacks)
vendor_redhat·2009-02-16·CVSS 7.5
CVE-2009-0652 [HIGH] firefox: does not properly prevent the literal rendering of homoglyph characters in IDN domain names (spoof URLs and conduct phishing attacks)
firefox: does not properly prevent the literal rendering of homoglyph characters in IDN domain names (spoof URLs and conduct phishing attacks)
The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233. NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.
GHSA
GHSA-h8qx-x78q-837g: The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3
ghsa_unreviewed·2022-05-02·CVSS 7.5
CVE-2009-0652 [HIGH] GHSA-h8qx-x78q-837g: The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3
The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233. NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.
No detection rules found.
CWE
Insufficient Visual Distinction of Homoglyphs Presented to User
mitre_cwe
CWE-1007 Insufficient Visual Distinction of Homoglyphs Presented to User
CWE-1007: Insufficient Visual Distinction of Homoglyphs Presented to User
The product displays information or identifiers to a user, but the display mechanism does not make it easy for the user to distinguish between visually similar or identical glyphs (homoglyphs), which may cause the user to misinterpret a glyph and perform an unintended, insecure action.
Some glyphs, pictures, or icons can be semantically distinct to a program, while appearing very similar or identical to a human user. These are referred to as homoglyphs. For example, the lowercase "l" (ell) and uppercase "I" (eye) have different character codes, but these characters can be displayed in exactly the same way to a user, depending on the font. This can also occur between different character sets. For example, the Latin
CAPEC
Homograph Attack via Homoglyphs
mitre_capec
[MEDIUM] Homograph Attack via Homoglyphs
CAPEC-632: Homograph Attack via Homoglyphs
An adversary registers a domain name containing a homoglyph, leading the registered domain to appear the same as a trusted domain. A homograph attack leverages the fact that different characters among various character sets look the same to the user. Homograph attacks must generally be combined with other attacks, such as phishing attacks, in order to direct Internet traffic to the adversary-controlled destinations.
Alternate Terms: Homoglyph Attack
Execution Flow:
Step 1 [Explore]: [Determine target website] The adversary first determines which website to impersonate, generally one that is trusted and receives a consistent amount of traffic.
Technique: Research popular or high traffic websites.
Step 2 [Experiment]: [Impersonate trusted domain]
http://lists.immunitysec.com/pipermail/dailydave/2009-February/005556.htmlhttp://lists.immunitysec.com/pipermail/dailydave/2009-February/005563.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.htmlhttp://rhn.redhat.com/errata/RHSA-2009-0437.htmlhttp://secunia.com/advisories/34096http://secunia.com/advisories/34843http://secunia.com/advisories/34844http://secunia.com/advisories/34894http://secunia.com/advisories/35042http://secunia.com/advisories/35065http://www.blackhat.com/html/bh-dc-09/bh-dc-09-speakers.html#Marlinspikehttp://www.debian.org/security/2009/dsa-1797http://www.debian.org/security/2009/dsa-1830http://www.mandriva.com/security/advisories?name=MDVSA-2009:111http://www.mozilla.org/security/announce/2009/mfsa2009-15.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0436.htmlhttp://www.securityfocus.com/bid/33837http://www.vupen.com/english/advisories/2009/1125https://exchange.xforce.ibmcloud.com/vulnerabilities/48974https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11396https://usn.ubuntu.com/764-1/https://www.blackhat.com/presentations/bh-dc-09/Marlinspike/BlackHat-DC-09-Marlinspike-Defeating-SSL.pdfhttps://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.htmlhttp://lists.immunitysec.com/pipermail/dailydave/2009-February/005556.htmlhttp://lists.immunitysec.com/pipermail/dailydave/2009-February/005563.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.htmlhttp://rhn.redhat.com/errata/RHSA-2009-0437.htmlhttp://secunia.com/advisories/34096http://secunia.com/advisories/34843http://secunia.com/advisories/34844http://secunia.com/advisories/34894http://secunia.com/advisories/35042http://secunia.com/advisories/35065http://www.blackhat.com/html/bh-dc-09/bh-dc-09-speakers.html#Marlinspikehttp://www.debian.org/security/2009/dsa-1797http://www.debian.org/security/2009/dsa-1830http://www.mandriva.com/security/advisories?name=MDVSA-2009:111http://www.mozilla.org/security/announce/2009/mfsa2009-15.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0436.htmlhttp://www.securityfocus.com/bid/33837http://www.vupen.com/english/advisories/2009/1125https://exchange.xforce.ibmcloud.com/vulnerabilities/48974https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11396https://usn.ubuntu.com/764-1/https://www.blackhat.com/presentations/bh-dc-09/Marlinspike/BlackHat-DC-09-Marlinspike-Defeating-SSL.pdfhttps://www.redhat.com/archives/fedora-package-announce/2009-April/msg00683.html
2009-02-20
Published