CVE-2015-4476
published 2015-09-24CVE-2015-4476: Mozilla Firefox before 41.0 on Android allows user-assisted remote attackers to spoof address-bar attributes by leveraging lack of navigation after a paste of…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.84%
76.9th percentile
Mozilla Firefox before 41.0 on Android allows user-assisted remote attackers to spoof address-bar attributes by leveraging lack of navigation after a paste of a URL with a nonstandard scheme, as demonstrated by spoofing an SSL attribute.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 40.0.3 | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jj3v-jj5r-gj49: Mozilla Firefox before 41
ghsa_unreviewed·2022-05-17
CVE-2015-4476 [MEDIUM] GHSA-jj3v-jj5r-gj49: Mozilla Firefox before 41
Mozilla Firefox before 41.0 on Android allows user-assisted remote attackers to spoof address-bar attributes by leveraging lack of navigation after a paste of a URL with a nonstandard scheme, as demonstrated by spoofing an SSL attribute.
Red Hat
Mozilla: Site attribute spoofing on Android by pasting URL with unknown scheme (MFSA 2015-99)
vendor_redhat·2015-09-22·CVSS 4.3
CVE-2015-4476 [MEDIUM] CWE-20 Mozilla: Site attribute spoofing on Android by pasting URL with unknown scheme (MFSA 2015-99)
Mozilla: Site attribute spoofing on Android by pasting URL with unknown scheme (MFSA 2015-99)
Mozilla Firefox before 41.0 on Android allows user-assisted remote attackers to spoof address-bar attributes by leveraging lack of navigation after a paste of a URL with a nonstandard scheme, as demonstrated by spoofing an SSL attribute.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 7) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
Custom URI schemes in the location bar can lead to Location Bar Spoofing
bugzilla·2016-12-25
[MEDIUM] Custom URI schemes in the location bar can lead to Location Bar Spoofing
Custom URI schemes in the location bar can lead to Location Bar Spoofing
Created attachment 8821806
Video Example.html
User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:50.0) Gecko/20100101 Firefox/50.0
Build ID: 20161208153507
Steps to reproduce:
On crafted webpage, copy a custom URL scheme (eg: secure://www.google.com/ ),
paste this custom URL scheme into the Address Bar,
and after, press the "Go to" button on the keyboard (like shown on the demonstration video uploaded in this Bug report).
-1 : Copy a custom URL scheme like secure://www.google.com and paste it into the Addressbar
-2 : Press the "Go to" button on the keyboard to try to go on this address
Actual results:
The Location Bar shows the custom URL scheme address (eg: secure://www.google.com ) leading to a Lo
Bugzilla
CVE-2015-4476 Mozilla: Site attribute spoofing on Android by pasting URL with unknown scheme (MFSA 2015-99)
bugzilla·2015-09-23·CVSS 4.3
CVE-2015-4476 [MEDIUM] CVE-2015-4476 Mozilla: Site attribute spoofing on Android by pasting URL with unknown scheme (MFSA 2015-99)
CVE-2015-4476 Mozilla: Site attribute spoofing on Android by pasting URL with unknown scheme (MFSA 2015-99)
ecurity researcher Jordi Chancel reported that on Firefox for Android, when a
URL is pasted with an unknown protocol, such as secure: or httpz, the pasted
URL is shown in the addressbar but no navigation occurs. Other address bar
attributes present before this pasted URL is entered will continue to be
rendered. This could lead to potential spoofing by a malicious site.
This issue only affects Firefox for Android and does not affect Firefox on
OS X, Linux, or Windows operating systems.
Upstream bug:
https://bugzilla.mozilla.org/show_bug.cgi?id=1162372
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2015-99/
Discussion:
Acknowledgements:
Red Hat woul
http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00000.htmlhttp://www.mozilla.org/security/announce/2015/mfsa2015-99.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/76815http://www.securitytracker.com/id/1033640https://bugzilla.mozilla.org/show_bug.cgi?id=1162372http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00000.htmlhttp://www.mozilla.org/security/announce/2015/mfsa2015-99.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/76815http://www.securitytracker.com/id/1033640https://bugzilla.mozilla.org/show_bug.cgi?id=1162372
2015-09-24
Published