in last 10 minutes
Google Gmail cross-site request forgery vulnerability
Google Gmail cross-site request forgery vulnerability
Overview
According to public reports, Google Gmail contained a cross-site request forgery (XSRF) vulnerability that allowed attackers to create email filters that could forward mail and attachments to arbitrary email addresses.I. Description
Google Gmail is a web based mail service. Gmail provides support for email filters that allow users to sort and forward mail.According to a report on the GNUCITIZEN site, Gmail contained a cross-site request forgery (XSRF) vulnerability that allowed attackers to create mail filters and forward mail to arbitrary email addresses. To exploit this vulnerability, an attacker would have had to convince a user to click or open a specially crafted hyperlink while the user was logged into their Gmail account. The hyperlink would have contained a http POST request that created the mail filter.
II. Impact
A remote attacker could have collected email addresses, emails, and attachments from a user's Gmail account.
III. Solution
According to publicly available reports, Google has addressed this vulnerability.
The following workarounds may partially mitigate future cross-site scripting (XSS) and XSRF vulnerabilities.
Workarounds for Users
- Using Gmail's SMTP and POP servers to send and receive mail will mitigate vulnerabilities in the Gmail web interface.
- The NoScript Firefox extension may mitigate XSRF and XSS vulnerabilities by restricting what sites can execute javascript and send cross-site POST requests.
- Encrypting sensitive emails and attachments will limit the impact of XSRF or other authentication bypass vulnerabilities.
- Blacklisting known XSS or XSRF exploit URLs using proxy server or application firewall rules at the network permiter may prevent some vulnerabilities from being exploited. Note that this workaround will not stop all known XSS or XSRF attack vectors.
Systems Affected
| Vendor | Status | Date Updated |
|---|---|---|
| Vulnerable | 1-Oct-2007 |
References
http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/
http://www.w3.org/Protocols/rfc2616/rfc2616-sec9.html
http://mail.google.com/support/bin/answer.py?hl=en&answer=13273
http://noscript.net/
http://www.cert.org/homeusers/email_postcard.html
Credit
Information about this vulnerability was disclosed on the GNUCITIZEN website.
This document was written by Ryan Giobbi.
Other Information
| Date Public | 25.09.2007 |
| Date First Published | 01.10.2007 11:30:17 |
| Date Last Updated | 01.10.2007 |
| CERT Advisory | |
| CVE Name | |
| Metric | 0,79 |
| Document Revision | 15 |
If you have feedback, comments, or additional information about this vulnerability, please send us email.
|
|||||||||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||||||||
in last 30 minutes
Contributors
Product
- ActiveX
- Adobe Flash Player
- Apple Mail
- Firefox
- IE
- Lotus Notes
- Mac OS X
- OpenSSL
- QuickTime
- Apple QuickTime RTSP Content-Type header stack buffer overflow
- Apple QuickTime RTSP Response message Reason-Phrase buffer overflow vulnerability
- Apple QuickTime buffer overflow vulnerability
- Apple QuickTime code execution vulnerability
- Apple QuickTime for Java may allow Java applets to gain elevated privileges
- Apple QuickTime heap buffer overflow vulnerability
- Safari
- SSH
- Windows Vista
- Microsoft DirectX
Company
- Adobe
- AOL
- Apple
- Apple Mac OS X CoreText uninitialized pointer vulnerability
- Apple Mail remote command execution vulnerability
- Apple QuickTime RTSP Content-Type header stack buffer overflow
- Apple QuickTime RTSP Response message Reason-Phrase buffer overflow vulnerability
- Apple QuickTime buffer overflow vulnerability
- Apple QuickTime code execution vulnerability
- Apple QuickTime for Java may allow Java applets to gain elevated privileges
- Apple QuickTime heap buffer overflow vulnerability
- Apple Safari code execution vulnerability
- Cisco
- Guidance Software
- IBM
- Microsoft
- Gateway CWebLaunchCtl ActiveX control buffer overflow
- Invensys Wonderware InTouch creates insecure NetDDE share
- Microsoft DirectX SAMI parsing buffer overflow
- Microsoft DirectX remote code execution
- Microsoft Exchange Outlook Web Access UTF character set label script injection vulnerability
- Microsoft Internet Explorer vulnerable to remote code execution
- Microsoft Kodak Image Viewer code execution vulnerability
- Microsoft MFC FindFile function heap buffer overflow
- Microsoft Outlook and Microsoft Exchange TNEF decoding buffer overflow
- Microsoft SMBv2 signing vulnerability
- Microsoft Windows DNS Server vulnerable to cache poisoning
- Microsoft Windows IGMPv3 and MLDv2 processing vulnerability
- Microsoft Windows LSASS privilege escalation vulnerability
- Microsoft Windows Media Format Runtime ASF handling buffer overflow
- Microsoft Windows Vista privilege escalation vulnerability
- SonicWall NetExtender NELaunchCtrl ActiveX control stack buffer overflow
- RealNetworks
- Sun
Attack
- XSS
- Adobe Flash Player asfunction protocol may enable cross-site scripting
- Adobe Flash Player fails to properly validate HTTP Referers
- Google Gmail cross-site request forgery vulnerability
- Microsoft Exchange Outlook Web Access UTF character set label script injection vulnerability
- Mortbay Jetty Dump Servlet vulnerable to cross-site scripting
- Mortbay Jetty fails to properly handle cookies with quotes
- Mortbay Jetty vulnerable to HTTP response splitting
- Mozilla Firefox jar URI cross-site scripting vulnerability
- RSA Keon cross-site scripting vulnerabilities
- Buffer Overflow
- AOL Radio AOLMediaPlaybackControl.exe stack buffer overflow
- Apple QuickTime RTSP Content-Type header stack buffer overflow
- Apple QuickTime RTSP Response message Reason-Phrase buffer overflow vulnerability
- Apple QuickTime buffer overflow vulnerability
- Apple QuickTime code execution vulnerability
- Apple QuickTime heap buffer overflow vulnerability
- Apple Safari code execution vulnerability
- CUPS buffer overflow vulnerability
- Cisco IOS LPD buffer overflow vulnerability
- Microsoft MFC FindFile function heap buffer overflow
- Microsoft Windows Media Format Runtime ASF handling buffer overflow
- RealNetworks player "Lyrics3" buffer overflow
- RealPlayer playlist name stack buffer overflow
- SonicWall NetExtender NELaunchCtrl ActiveX control stack buffer overflow
- libFLAC contains multiple vulnerabilities
- DOS
Programming Language
- JavaScript
- Java
