The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a long user:pass sequence in the URL, which appears before the real hostname.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Firefox | Mozilla | 0.8 (including) | 0.8 (including) |
Firefox | Mozilla | 0.9 (including) | 0.9 (including) |
Firefox | Mozilla | 0.9-rc (including) | 0.9-rc (including) |
Firefox | Mozilla | 0.9.1 (including) | 0.9.1 (including) |
Firefox | Mozilla | 0.9.2 (including) | 0.9.2 (including) |
Firefox | Mozilla | 0.9.3 (including) | 0.9.3 (including) |
Firefox | Mozilla | 0.10 (including) | 0.10 (including) |
Firefox | Mozilla | 0.10.1 (including) | 0.10.1 (including) |
Firefox | Mozilla | 1.0 (including) | 1.0 (including) |
Mozilla | Mozilla | 1.3 (including) | 1.3 (including) |
Mozilla | Mozilla | 1.4 (including) | 1.4 (including) |
Mozilla | Mozilla | 1.4-alpha (including) | 1.4-alpha (including) |
Mozilla | Mozilla | 1.4.1 (including) | 1.4.1 (including) |
Mozilla | Mozilla | 1.5 (including) | 1.5 (including) |
Mozilla | Mozilla | 1.5-alpha (including) | 1.5-alpha (including) |
Mozilla | Mozilla | 1.5-rc1 (including) | 1.5-rc1 (including) |
Mozilla | Mozilla | 1.5-rc2 (including) | 1.5-rc2 (including) |
Mozilla | Mozilla | 1.5.1 (including) | 1.5.1 (including) |
Mozilla | Mozilla | 1.6 (including) | 1.6 (including) |
Mozilla | Mozilla | 1.6-alpha (including) | 1.6-alpha (including) |
Mozilla | Mozilla | 1.6-beta (including) | 1.6-beta (including) |
Mozilla | Mozilla | 1.7 (including) | 1.7 (including) |
Mozilla | Mozilla | 1.7-alpha (including) | 1.7-alpha (including) |
Mozilla | Mozilla | 1.7-beta (including) | 1.7-beta (including) |
Mozilla | Mozilla | 1.7-rc1 (including) | 1.7-rc1 (including) |
Mozilla | Mozilla | 1.7-rc2 (including) | 1.7-rc2 (including) |
Mozilla | Mozilla | 1.7-rc3 (including) | 1.7-rc3 (including) |
Mozilla | Mozilla | 1.7.1 (including) | 1.7.1 (including) |
Mozilla | Mozilla | 1.7.2 (including) | 1.7.2 (including) |
Mozilla | Mozilla | 1.7.3 (including) | 1.7.3 (including) |
Mozilla | Mozilla | 1.7.5 (including) | 1.7.5 (including) |
Thunderbird | Mozilla | 0.1 (including) | 0.1 (including) |
Thunderbird | Mozilla | 0.2 (including) | 0.2 (including) |
Thunderbird | Mozilla | 0.3 (including) | 0.3 (including) |
Thunderbird | Mozilla | 0.4 (including) | 0.4 (including) |
Thunderbird | Mozilla | 0.5 (including) | 0.5 (including) |
Thunderbird | Mozilla | 0.6 (including) | 0.6 (including) |
Thunderbird | Mozilla | 0.7 (including) | 0.7 (including) |
Thunderbird | Mozilla | 0.7.1 (including) | 0.7.1 (including) |
Thunderbird | Mozilla | 0.7.2 (including) | 0.7.2 (including) |
Thunderbird | Mozilla | 0.7.3 (including) | 0.7.3 (including) |
Thunderbird | Mozilla | 0.8 (including) | 0.8 (including) |
Thunderbird | Mozilla | 0.9 (including) | 0.9 (including) |
Thunderbird | Mozilla | 1.0 (including) | 1.0 (including) |
Red Hat Enterprise Linux 2.1 | RedHat | galeon | * |
Red Hat Enterprise Linux 2.1 | RedHat | mozilla | * |
Red Hat Enterprise Linux 3 | RedHat | mozilla | * |
Red Hat Enterprise Linux 4 | RedHat | firefox-0:1.0.1-1.4.3 | * |
Mozilla | Ubuntu | edgy | * |