Mozilla Firefox and SeaMonkey contain a flaw related to the 'NS_SecurityCompareURIs' function in 'netwerk/base/public/nsNetUtil.h'. The function does not properly handle about:neterror and about:certerror pages, allowing a context-dependent attacker to use a maliciously crafted web site to spoof the location bar.
Classification
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Upgrade
Disclosure:
Vendor Verified
OSVDB:
Web Related
Solution
Upgrade Firefox to version 3.5.16 or 3.6.13 or higher and SeaMonkey to version 2.0.11 or higher, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.