Bug 151915

Summary: CVE-2004-1380 Input stealing from other tabs (CVE-2004-1381)
Product: Red Hat Enterprise Linux 2.1 Reporter: Josh Bressers <bressers>
Component: galeonAssignee: Christopher Aillon <caillon>
Status: CLOSED WONTFIX QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: 2.1CC: security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=moderate,public=20050120,reported=20050323
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2007-05-15 18:01:15 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Josh Bressers 2005-03-23 15:25:17 UTC
+++ This bug was initially created as a clone of Bug #145610 +++

===================================
Mozilla Security Advisory MSA05-005
===================================

Title:      Input stealing from other tabs
Severity:   High
Reporter:   Jakob Balle (Secunia)

Fixed in:   Firefox 1.0
            Mozilla Suite 1.7.5


Description
-----------
Jakob Balle of Secunia reported two vulnerabilities in windows with multiple
tabs. Malicious content in a background tab can attempt to steal information
intended for the topmost tab by popping up prompt dialog that appears to come
from the trusted site, or by silently redirecting input focus to a background
tab hoping to catch the user inputting something sensitive.

Jesse Ruderman and Martin Wargers discovered variants


Workaround
----------
Do not open sites with sensitive content in the same window as tabs from
untrusted content.
Upgrade to fixed version.


References
----------
http://secunia.com/advisories/12712
https://bugzilla.mozilla.org/show_bug.cgi?id=262887
https://bugzilla.mozilla.org/show_bug.cgi?id=265055
https://bugzilla.mozilla.org/show_bug.cgi?id=265456

Comment 1 Josh Bressers 2005-03-23 15:25:51 UTC
This issue does affect galeon.

Comment 14 Christopher Aillon 2007-05-15 18:01:15 UTC
Yeah I guess it can be now.