Novell Home

CVE-2009-0777

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2009-0777 at MITRE

Description

Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks.

NVD CVSS v2 Base Score: 5.8 (AV:N/AC:M/Au:N/C:N/I:P/A:P)

Novell/SUSE information

Novell Bugzilla entry: 478625

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References

List of products where fixes are in QA

© 2012 Novell