Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 887259 - (CVE-2005-2395) CVE-2005-2395 firefox: Does not choose the challenge with the strongest authentication scheme available as required by RFC2617
CVE-2005-2395 firefox: Does not choose the challenge with the strongest authe...
Status: CLOSED WONTFIX
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
impact=low,public=20040117,reported=2...
: Security
Depends On: 1364463
Blocks: 887261
  Show dependency treegraph
 
Reported: 2012-12-14 08:34 EST by Jan Lieskovsky
Modified: 2016-11-08 10:55 EST (History)
4 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2013-01-16 01:39:01 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Jan Lieskovsky 2012-12-14 08:34:02 EST
Common Vulnerabilities and Exposures assigned an identifier CVE-2005-2395 to the following vulnerability:

Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if an encrypted channel is available.

References:
[1] http://www.securityfocus.com/archive/1/405666
[2] https://bugzilla.mozilla.org/show_bug.cgi?id=281851
[3] http://www.securiteam.com/securitynews/5PP0L00GUQ.html
[4] http://www.securityfocus.com/bid/14325
[5] http://www.osvdb.org/19002
[6] http://securityreason.com/securityalert/8
[7] http://xforce.iss.net/xforce/xfdb/22272
[8] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=228174
Comment 1 Huzaifa S. Sidhpurwala 2013-01-16 01:39:01 EST
Note:

Upstream bug comments suggests that Mozilla does not plan to address this issue in the short term. This seems to affects the version of Firefox shipped with Red Hat Enterprise Linux 5 and 6, and also Fedora.

Closing this bug as WONTFIX currently.

Note You need to log in before you can comment on or make changes to this bug.