Bug#320539: weak authentication mechanism vulnerability (CAN-2005-2395)

2005-09-18 Thread Eric Dorland
forwarded 320539 https://bugzilla.mozilla.org/show_bug.cgi?id=281851 thanks * Joey Hess ([EMAIL PROTECTED]) wrote: > Package: mozilla-firefox > Version: 1.0.5-1 > Severity: important > > I've tested firefox to be vulnerable to CAN-2005-2395. > > Mozilla Firefox 1.0.4 and 1.0.5 does not choose th

Bug#320539: weak authentication mechanism vulnerability (CAN-2005-2395)

2005-07-29 Thread Joey Hess
Package: mozilla-firefox Version: 1.0.5-1 Severity: important I've tested firefox to be vulnerable to CAN-2005-2395. Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent i