CVE-2009-1834
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
12/06/2009
Last modified:
09/04/2025
Description
Visual truncation vulnerability in netwerk/dns/src/nsIDNService.cpp in Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 allows remote attackers to spoof the location bar via an IDN with invalid Unicode characters that are displayed as whitespace, as demonstrated by the \u115A through \u115E characters.
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | 3.0.10 (including) | |
| cpe:2.3:a:mozilla:firefox:0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:0.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:0.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:0.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:0.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:0.6.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:0.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:0.7.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:0.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:0.9:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:0.9:rc:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:0.9.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:mozilla:firefox:0.9.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://osvdb.org/55162
- http://secunia.com/advisories/35331
- http://secunia.com/advisories/35415
- http://secunia.com/advisories/35431
- http://secunia.com/advisories/35439
- http://secunia.com/advisories/35468
- http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.372468
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1
- http://www.debian.org/security/2009/dsa-1820
- http://www.mozilla.org/security/announce/2009/mfsa2009-25.html
- http://www.securityfocus.com/bid/35326
- http://www.securityfocus.com/bid/35388
- http://www.vupen.com/english/advisories/2009/1572
- https://bugzilla.mozilla.org/show_bug.cgi?id=479413
- https://bugzilla.redhat.com/show_bug.cgi?id=503573
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10436
- https://rhn.redhat.com/errata/RHSA-2009-1095.html
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00574.html
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00657.html
- http://osvdb.org/55162
- http://secunia.com/advisories/35331
- http://secunia.com/advisories/35415
- http://secunia.com/advisories/35431
- http://secunia.com/advisories/35439
- http://secunia.com/advisories/35468
- http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.372468
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1
- http://www.debian.org/security/2009/dsa-1820
- http://www.mozilla.org/security/announce/2009/mfsa2009-25.html
- http://www.securityfocus.com/bid/35326
- http://www.securityfocus.com/bid/35388
- http://www.vupen.com/english/advisories/2009/1572
- https://bugzilla.mozilla.org/show_bug.cgi?id=479413
- https://bugzilla.redhat.com/show_bug.cgi?id=503573
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10436
- https://rhn.redhat.com/errata/RHSA-2009-1095.html
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00574.html
- https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00657.html



