Firefox before 1.0 and Mozilla before 1.7.5, when configured to use a proxy, respond to 407 proxy auth requests from arbitrary servers, which allows remote attackers to steal NTLM or SPNEGO credentials.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Firefox | Mozilla | 0.8 (including) | 0.8 (including) |
| Firefox | Mozilla | 0.9 (including) | 0.9 (including) |
| Firefox | Mozilla | 0.9.1 (including) | 0.9.1 (including) |
| Firefox | Mozilla | 0.9.2 (including) | 0.9.2 (including) |
| Firefox | Mozilla | 0.9.3 (including) | 0.9.3 (including) |
| Mozilla | Mozilla | 1.7 (including) | 1.7 (including) |
| Mozilla | Mozilla | 1.7-rc3 (including) | 1.7-rc3 (including) |
| Mozilla | Mozilla | 1.7.1 (including) | 1.7.1 (including) |
| Mozilla | Mozilla | 1.7.2 (including) | 1.7.2 (including) |
| Mozilla | Mozilla | 1.7.3 (including) | 1.7.3 (including) |
| Red Hat Enterprise Linux 2.1 | RedHat | galeon | * |
| Red Hat Enterprise Linux 2.1 | RedHat | mozilla | * |
| Red Hat Enterprise Linux 3 | RedHat | mozilla | * |
| Mozilla | Ubuntu | edgy | * |