Bug 445357 (CVE-2008-1999)
Summary: | CVE-2008-1999 WebKit: address bar spoofing using URLs with spaces | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Tomas Hoger <thoger> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED NOTABUG | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | mtasaka, peter, wnefal+redhatbugzilla |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1999 | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2011-02-05 09:54:22 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Tomas Hoger
2008-05-06 14:02:12 UTC
Even though this CVE is worded as affecting Apple Safari, this issue is probably in WebKit. Test case causes both kazehakase(-webkit) and midori to display spoofed URL as: attacker_controlled_prefix<spaces ... spaces>@real_url Depending on the with of your browser window, you may only see attacker_controlled_prefix part of the URL, which may trick you to believe you are currently visiting different site. If you switch kazehakase to use gecko, it will: - warn you that you are trying to log to a site that does not require authentication - display %-encoded sequence in address bar (same behavior as you get with e.g. firefox) I haven't checked WebKit SVN whether there is any fix for this already. Tested with: WebKit-gtk-1.0.0-0.8.svn32416 r32901 seems no good (however would you check it?) http://koji.fedoraproject.org/koji/taskinfo?taskID=597635 Yes, r32901 / WebKit-1.0.0-0.9.svn32901 still affected. No change with WebKit-1.0.0-0.10.svn34655 The geocities page with the proof of concept is gone. I can't find any reference that this was fixed, but considering how old this is and that we currently have webkitgtk 1.2.x, I imagine this is fixed, but can't verify. Does someone have a local copy of this PoC? I also can't find anything in the upstream webkit bts so no idea if this has been addressed or not. There is nothing webkit can do in here. URL handling is handled by the browser layer. |