Bug 887259 (CVE-2005-2395)

Summary: CVE-2005-2395 firefox: Does not choose the challenge with the strongest authentication scheme available as required by RFC2617
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED WONTFIX QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: gecko-bugs-nobody, gecko-bugs-nobody, jhorak, stransky
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-01-16 06:39:01 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1364463    
Bug Blocks: 887261    

Description Jan Lieskovsky 2012-12-14 13:34:02 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2005-2395 to the following vulnerability:

Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if an encrypted channel is available.

References:
[1] http://www.securityfocus.com/archive/1/405666
[2] https://bugzilla.mozilla.org/show_bug.cgi?id=281851
[3] http://www.securiteam.com/securitynews/5PP0L00GUQ.html
[4] http://www.securityfocus.com/bid/14325
[5] http://www.osvdb.org/19002
[6] http://securityreason.com/securityalert/8
[7] http://xforce.iss.net/xforce/xfdb/22272
[8] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=228174

Comment 1 Huzaifa S. Sidhpurwala 2013-01-16 06:39:01 UTC
Note:

Upstream bug comments suggests that Mozilla does not plan to address this issue in the short term. This seems to affects the version of Firefox shipped with Red Hat Enterprise Linux 5 and 6, and also Fedora.

Closing this bug as WONTFIX currently.