Bug#320539: weak authentication mechanism vulnerability (CAN-2005-2395)

2005-09-18 Thread Eric Dorland
forwarded 320539 https://bugzilla.mozilla.org/show_bug.cgi?id=281851 thanks * Joey Hess ([EMAIL PROTECTED]) wrote: Package: mozilla-firefox Version: 1.0.5-1 Severity: important I've tested firefox to be vulnerable to CAN-2005-2395. Mozilla Firefox 1.0.4 and 1.0.5 does not choose the

Bug#320539: weak authentication mechanism vulnerability (CAN-2005-2395)

2005-07-29 Thread Joey Hess
Package: mozilla-firefox Version: 1.0.5-1 Severity: important I've tested firefox to be vulnerable to CAN-2005-2395. Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent