Closed
Bug 1161886
Opened 11 years ago
Closed 11 years ago
Firefox leaves important websites vulnerables to clickjacking
Categories
(Firefox :: General, defect)
Tracking
()
RESOLVED
FIXED
People
(Reporter: santiagoalopez.sl, Unassigned)
Details
(Keywords: csectype-clickjacking)
Attachments
(1 file)
|
61 bytes,
text/html
|
Details |
How the name says, this Firefox vulnerabilitie leaves important websites vulnerable to clickjacking. Ex: https://www.mozilla.org, etc.
With the HTML exploit, i execute it in the browser and i see that the iframe is showing the website. So, an attacker can do a clickjacking attack to that website and change the account settings of the victim.
PD: This vulnerabilitie only works in Debian, my version is 6.0.1.
Comment 1•11 years ago
|
||
Debian 6.0.1 has an ancient version of Firefox/Iceweasel (3.5.something) which is no longer supported. It is Debian's issue if they don't ship a version that has security fixes. On modern versions of Firefox, the frame loads nothing and produces an error:
Load denied by X-Frame-Options: https://www.mozilla.org/en-US/ does not permit framing.
Group: core-security
Status: UNCONFIRMED → RESOLVED
Closed: 11 years ago
Resolution: --- → FIXED
Comment 2•11 years ago
|
||
(In reply to :Gijs Kruitbosch from comment #1)
> Debian 6.0.1 has an ancient version of Firefox/Iceweasel (3.5.something)
> which is no longer supported. It is Debian's issue if they don't ship a
> version that has security fixes.
More importantly, Debian 6 *is* an ancient version of Debian which is no longer supported, and hasn't been for about one year. As for Iceweasel in Debian 6, it hasn't been supported for 2 years.
Updated•2 years ago
|
Keywords: csectype-clickjacking
You need to log in
before you can comment on or make changes to this bug.
Description
•