Bug#294439: mozilla-firefox: Phishing vulnerability using IDN

2005-02-09 Thread C. Scott Ananian
On Wed, 9 Feb 2005, Eric Dorland wrote: Please don't file duplicate bug reports. Sorry, didn't see the other one. There are 241 open bugs on firefox, and reportbug sorts the forwarded bugs after all others, so this (very serious) bug gets listed after 50-some-odd wishlist items. My bad for not

Bug#294439: mozilla-firefox: Phishing vulnerability using IDN

2005-02-09 Thread Eric Dorland
merge 293975 294439 thanks Please don't file duplicate bug reports. * C. Scott Ananian ([EMAIL PROTECTED]) wrote: > Package: mozilla-firefox > Version: 1.0+dfsg.1-5 > Severity: grave > Justification: user security hole > > > "Homograph attack" allows an attacker to create a link, with SSL 'lock

Bug#294439: mozilla-firefox: Phishing vulnerability using IDN

2005-02-09 Thread C. Scott Ananian
Package: mozilla-firefox Version: 1.0+dfsg.1-5 Severity: grave Justification: user security hole "Homograph attack" allows an attacker to create a link, with SSL 'lock' and everything which is indistinguishable from a trusted site. Advisory is here: http://www.shmoo.com/idn/homograph.txt Exam