Overview
Google Reader is vulnerable to a persistent cross-site request forgery attack that may be exploited by a specially crafted RSS feed.
Description
Google Reader is an online RSS feed reader. It can display text and images when displaying RSS feeds. Google Reader contains a cross-site request forgery (XSRF) vulnerability that could be used to prevent a user from logging on to the service. |
Impact
A remote unauthenticated attacker may be able to prevent a user from logging in to Google Reader. |
Solution
We are currently unaware of a practical solution to this problem, however the following workarounds may help mitigate the vulnerability. |
Do not load images from third party sites |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://reader.google.com
- http://www.gnucitizen.org/blog/persistent-csrf-and-the-hotlink-hell/
- http://www.microsoft.com/enable/training/ie6/pictures.aspx
- http://kb.mozillazine.org/Permissions.default.image
- http://michaeldaw.org/papers/hotlink_persistent_csrf
- http://en.wikipedia.org/wiki/Cross-site_request_forgery
Acknowledgements
This issue was reported on the GNUCITIZEN blog.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | None |
Severity Metric: | 0.84 |
Date Public: | 2007-04-16 |
Date First Published: | 2007-04-18 |
Date Last Updated: | 2007-09-12 17:22 UTC |
Document Revision: | 6 |