MEDIUM · 4.3

CVE-2007-2292

CRLF injection vulnerability in the Digest Authentication support for Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allows remote attackers to conduct HTTP request splitting attacks via LF...

Vulnerability Description

CRLF injection vulnerability in the Digest Authentication support for Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allows remote attackers to conduct HTTP request splitting attacks via LF (%0a) bytes in the username attribute.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
MicrosoftInternet Explorer7.0.5730.11
MozillaFirefox<= 2.0.0.8
MozillaSeamonkey<= 1.1.5

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-2292?

CVE-2007-2292 is a vulnerability with a CVSS score of 4.3 (MEDIUM). CRLF injection vulnerability in the Digest Authentication support for Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allows remote attackers to conduct HTTP request splitting attacks via LF...

How severe is CVE-2007-2292?

CVE-2007-2292 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-2292?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Internet Explorer, Mozilla Firefox, Mozilla Seamonkey.