CVE Vulnerabilities

CVE-2009-1836

Improper Authentication

Published: Jun 12, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
1.8 MODERATE
AV:A/AC:H/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document provided in a non-200 CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an SSL tampering attack.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla*3.0.10 (including)
FirefoxMozilla0.1 (including)0.1 (including)
FirefoxMozilla0.2 (including)0.2 (including)
FirefoxMozilla0.3 (including)0.3 (including)
FirefoxMozilla0.4 (including)0.4 (including)
FirefoxMozilla0.5 (including)0.5 (including)
FirefoxMozilla0.6 (including)0.6 (including)
FirefoxMozilla0.6.1 (including)0.6.1 (including)
FirefoxMozilla0.7 (including)0.7 (including)
FirefoxMozilla0.7.1 (including)0.7.1 (including)
FirefoxMozilla0.8 (including)0.8 (including)
FirefoxMozilla0.9 (including)0.9 (including)
FirefoxMozilla0.9-rc (including)0.9-rc (including)
FirefoxMozilla0.9.1 (including)0.9.1 (including)
FirefoxMozilla0.9.2 (including)0.9.2 (including)
FirefoxMozilla0.9.3 (including)0.9.3 (including)
FirefoxMozilla0.9_rc (including)0.9_rc (including)
FirefoxMozilla0.10 (including)0.10 (including)
FirefoxMozilla0.10.1 (including)0.10.1 (including)
FirefoxMozilla1.0 (including)1.0 (including)
FirefoxMozilla1.0-preview_release (including)1.0-preview_release (including)
FirefoxMozilla1.0.1 (including)1.0.1 (including)
FirefoxMozilla1.0.2 (including)1.0.2 (including)
FirefoxMozilla1.0.3 (including)1.0.3 (including)
FirefoxMozilla1.0.4 (including)1.0.4 (including)
FirefoxMozilla1.0.5 (including)1.0.5 (including)
FirefoxMozilla1.0.6 (including)1.0.6 (including)
FirefoxMozilla1.0.7 (including)1.0.7 (including)
FirefoxMozilla1.0.8 (including)1.0.8 (including)
FirefoxMozilla1.4.1 (including)1.4.1 (including)
FirefoxMozilla1.5 (including)1.5 (including)
FirefoxMozilla1.5-beta1 (including)1.5-beta1 (including)
FirefoxMozilla1.5-beta2 (including)1.5-beta2 (including)
FirefoxMozilla1.5.0.1 (including)1.5.0.1 (including)
FirefoxMozilla1.5.0.2 (including)1.5.0.2 (including)
FirefoxMozilla1.5.0.3 (including)1.5.0.3 (including)
FirefoxMozilla1.5.0.4 (including)1.5.0.4 (including)
FirefoxMozilla1.5.0.5 (including)1.5.0.5 (including)
FirefoxMozilla1.5.0.6 (including)1.5.0.6 (including)
FirefoxMozilla1.5.0.7 (including)1.5.0.7 (including)
FirefoxMozilla1.5.0.8 (including)1.5.0.8 (including)
FirefoxMozilla1.5.0.9 (including)1.5.0.9 (including)
FirefoxMozilla1.5.0.10 (including)1.5.0.10 (including)
FirefoxMozilla1.5.0.11 (including)1.5.0.11 (including)
FirefoxMozilla1.5.0.12 (including)1.5.0.12 (including)
FirefoxMozilla1.5.1 (including)1.5.1 (including)
FirefoxMozilla1.5.2 (including)1.5.2 (including)
FirefoxMozilla1.5.3 (including)1.5.3 (including)
FirefoxMozilla1.5.4 (including)1.5.4 (including)
FirefoxMozilla1.5.5 (including)1.5.5 (including)
FirefoxMozilla1.5.6 (including)1.5.6 (including)
FirefoxMozilla1.5.7 (including)1.5.7 (including)
FirefoxMozilla1.5.8 (including)1.5.8 (including)
FirefoxMozilla1.8 (including)1.8 (including)
FirefoxMozilla2.0 (including)2.0 (including)
FirefoxMozilla2.0-beta_1 (including)2.0-beta_1 (including)
FirefoxMozilla2.0-beta1 (including)2.0-beta1 (including)
FirefoxMozilla2.0-rc2 (including)2.0-rc2 (including)
FirefoxMozilla2.0-rc3 (including)2.0-rc3 (including)
FirefoxMozilla2.0.0.1 (including)2.0.0.1 (including)
FirefoxMozilla2.0.0.2 (including)2.0.0.2 (including)
FirefoxMozilla2.0.0.3 (including)2.0.0.3 (including)
FirefoxMozilla2.0.0.4 (including)2.0.0.4 (including)
FirefoxMozilla2.0.0.5 (including)2.0.0.5 (including)
FirefoxMozilla2.0.0.6 (including)2.0.0.6 (including)
FirefoxMozilla2.0.0.7 (including)2.0.0.7 (including)
FirefoxMozilla2.0.0.8 (including)2.0.0.8 (including)
FirefoxMozilla2.0.0.9 (including)2.0.0.9 (including)
FirefoxMozilla2.0.0.10 (including)2.0.0.10 (including)
FirefoxMozilla2.0.0.11 (including)2.0.0.11 (including)
FirefoxMozilla2.0.0.12 (including)2.0.0.12 (including)
FirefoxMozilla2.0.0.13 (including)2.0.0.13 (including)
FirefoxMozilla2.0.0.14 (including)2.0.0.14 (including)
FirefoxMozilla2.0.0.15 (including)2.0.0.15 (including)
FirefoxMozilla2.0.0.16 (including)2.0.0.16 (including)
FirefoxMozilla2.0.0.17 (including)2.0.0.17 (including)
FirefoxMozilla2.0.0.18 (including)2.0.0.18 (including)
FirefoxMozilla2.0.0.19 (including)2.0.0.19 (including)
FirefoxMozilla2.0.0.20 (including)2.0.0.20 (including)
FirefoxMozilla2.0.0.21 (including)2.0.0.21 (including)
FirefoxMozilla2.0_.1 (including)2.0_.1 (including)
FirefoxMozilla2.0_.4 (including)2.0_.4 (including)
FirefoxMozilla2.0_.5 (including)2.0_.5 (including)
FirefoxMozilla2.0_.6 (including)2.0_.6 (including)
FirefoxMozilla2.0_.7 (including)2.0_.7 (including)
FirefoxMozilla2.0_.9 (including)2.0_.9 (including)
FirefoxMozilla2.0_.10 (including)2.0_.10 (including)
FirefoxMozilla2.0_8 (including)2.0_8 (including)
FirefoxMozilla3.0 (including)3.0 (including)
FirefoxMozilla3.0-alpha (including)3.0-alpha (including)
FirefoxMozilla3.0-beta2 (including)3.0-beta2 (including)
FirefoxMozilla3.0-beta5 (including)3.0-beta5 (including)
FirefoxMozilla3.0.1 (including)3.0.1 (including)
FirefoxMozilla3.0.2 (including)3.0.2 (including)
FirefoxMozilla3.0.3 (including)3.0.3 (including)
FirefoxMozilla3.0.4 (including)3.0.4 (including)
FirefoxMozilla3.0.5 (including)3.0.5 (including)
FirefoxMozilla3.0.6 (including)3.0.6 (including)
FirefoxMozilla3.0.7 (including)3.0.7 (including)
FirefoxMozilla3.0.8 (including)3.0.8 (including)
FirefoxMozilla3.0.9 (including)3.0.9 (including)
FirefoxMozilla3.0beta5 (including)3.0beta5 (including)
SeamonkeyMozilla*1.1.16 (including)
SeamonkeyMozilla1.0 (including)1.0 (including)
SeamonkeyMozilla1.0-alpha (including)1.0-alpha (including)
SeamonkeyMozilla1.0-beta (including)1.0-beta (including)
SeamonkeyMozilla1.0.1 (including)1.0.1 (including)
SeamonkeyMozilla1.0.3 (including)1.0.3 (including)
SeamonkeyMozilla1.0.4 (including)1.0.4 (including)
SeamonkeyMozilla1.0.6 (including)1.0.6 (including)
SeamonkeyMozilla1.0.8 (including)1.0.8 (including)
SeamonkeyMozilla1.0.9 (including)1.0.9 (including)
SeamonkeyMozilla1.0.99 (including)1.0.99 (including)
SeamonkeyMozilla1.1 (including)1.1 (including)
SeamonkeyMozilla1.1-alpha (including)1.1-alpha (including)
SeamonkeyMozilla1.1-beta (including)1.1-beta (including)
SeamonkeyMozilla1.1.1 (including)1.1.1 (including)
SeamonkeyMozilla1.1.3 (including)1.1.3 (including)
SeamonkeyMozilla1.1.5 (including)1.1.5 (including)
SeamonkeyMozilla1.1.5-1.1.10 (including)1.1.5-1.1.10 (including)
SeamonkeyMozilla1.1.6 (including)1.1.6 (including)
SeamonkeyMozilla1.1.7 (including)1.1.7 (including)
SeamonkeyMozilla1.1.8 (including)1.1.8 (including)
SeamonkeyMozilla1.1.9 (including)1.1.9 (including)
SeamonkeyMozilla1.1.10 (including)1.1.10 (including)
SeamonkeyMozilla1.1.11 (including)1.1.11 (including)
SeamonkeyMozilla1.1.12 (including)1.1.12 (including)
SeamonkeyMozilla1.1.13 (including)1.1.13 (including)
SeamonkeyMozilla1.1.15 (including)1.1.15 (including)
ThunderbirdMozilla*2.0.0.19 (including)
ThunderbirdMozilla0.1 (including)0.1 (including)
ThunderbirdMozilla0.2 (including)0.2 (including)
ThunderbirdMozilla0.3 (including)0.3 (including)
ThunderbirdMozilla0.4 (including)0.4 (including)
ThunderbirdMozilla0.5 (including)0.5 (including)
ThunderbirdMozilla0.6 (including)0.6 (including)
ThunderbirdMozilla0.7 (including)0.7 (including)
ThunderbirdMozilla0.7.1 (including)0.7.1 (including)
ThunderbirdMozilla0.7.2 (including)0.7.2 (including)
ThunderbirdMozilla0.7.3 (including)0.7.3 (including)
ThunderbirdMozilla0.8 (including)0.8 (including)
ThunderbirdMozilla0.9 (including)0.9 (including)
ThunderbirdMozilla1.0 (including)1.0 (including)
ThunderbirdMozilla1.0.1 (including)1.0.1 (including)
ThunderbirdMozilla1.0.2 (including)1.0.2 (including)
ThunderbirdMozilla1.0.3 (including)1.0.3 (including)
ThunderbirdMozilla1.0.4 (including)1.0.4 (including)
ThunderbirdMozilla1.0.5 (including)1.0.5 (including)
ThunderbirdMozilla1.0.5-beta (including)1.0.5-beta (including)
ThunderbirdMozilla1.0.6 (including)1.0.6 (including)
ThunderbirdMozilla1.0.7 (including)1.0.7 (including)
ThunderbirdMozilla1.0.8 (including)1.0.8 (including)
ThunderbirdMozilla1.5 (including)1.5 (including)
ThunderbirdMozilla1.5-beta2 (including)1.5-beta2 (including)
ThunderbirdMozilla1.5.0.1 (including)1.5.0.1 (including)
ThunderbirdMozilla1.5.0.2 (including)1.5.0.2 (including)
ThunderbirdMozilla1.5.0.3 (including)1.5.0.3 (including)
ThunderbirdMozilla1.5.0.4 (including)1.5.0.4 (including)
ThunderbirdMozilla1.5.0.5 (including)1.5.0.5 (including)
ThunderbirdMozilla1.5.0.6 (including)1.5.0.6 (including)
ThunderbirdMozilla1.5.0.7 (including)1.5.0.7 (including)
ThunderbirdMozilla1.5.0.8 (including)1.5.0.8 (including)
ThunderbirdMozilla1.5.0.9 (including)1.5.0.9 (including)
ThunderbirdMozilla1.5.0.10 (including)1.5.0.10 (including)
ThunderbirdMozilla1.5.0.11 (including)1.5.0.11 (including)
ThunderbirdMozilla1.5.0.12 (including)1.5.0.12 (including)
ThunderbirdMozilla1.5.0.13 (including)1.5.0.13 (including)
ThunderbirdMozilla1.5.0.14 (including)1.5.0.14 (including)
ThunderbirdMozilla1.5.1 (including)1.5.1 (including)
ThunderbirdMozilla1.5.2 (including)1.5.2 (including)
ThunderbirdMozilla1.7.1 (including)1.7.1 (including)
ThunderbirdMozilla1.7.3 (including)1.7.3 (including)
ThunderbirdMozilla2.0.0.0 (including)2.0.0.0 (including)
ThunderbirdMozilla2.0.0.1 (including)2.0.0.1 (including)
ThunderbirdMozilla2.0.0.2 (including)2.0.0.2 (including)
ThunderbirdMozilla2.0.0.3 (including)2.0.0.3 (including)
ThunderbirdMozilla2.0.0.4 (including)2.0.0.4 (including)
ThunderbirdMozilla2.0.0.5 (including)2.0.0.5 (including)
ThunderbirdMozilla2.0.0.6 (including)2.0.0.6 (including)
ThunderbirdMozilla2.0.0.7 (including)2.0.0.7 (including)
ThunderbirdMozilla2.0.0.8 (including)2.0.0.8 (including)
ThunderbirdMozilla2.0.0.9 (including)2.0.0.9 (including)
ThunderbirdMozilla2.0.0.11 (including)2.0.0.11 (including)
ThunderbirdMozilla2.0.0.12 (including)2.0.0.12 (including)
ThunderbirdMozilla2.0.0.13 (including)2.0.0.13 (including)
ThunderbirdMozilla2.0.0.14 (including)2.0.0.14 (including)
ThunderbirdMozilla2.0.0.15 (including)2.0.0.15 (including)
ThunderbirdMozilla2.0.0.16 (including)2.0.0.16 (including)
ThunderbirdMozilla2.0.0.17 (including)2.0.0.17 (including)
ThunderbirdMozilla2.0.0.18 (including)2.0.0.18 (including)
ThunderbirdMozilla2.0_.4 (including)2.0_.4 (including)
ThunderbirdMozilla2.0_.5 (including)2.0_.5 (including)
ThunderbirdMozilla2.0_.6 (including)2.0_.6 (including)
ThunderbirdMozilla2.0_.9 (including)2.0_.9 (including)
ThunderbirdMozilla2.0_.12 (including)2.0_.12 (including)
ThunderbirdMozilla2.0_.13 (including)2.0_.13 (including)
ThunderbirdMozilla2.0_.14 (including)2.0_.14 (including)
ThunderbirdMozilla2.0_8 (including)2.0_8 (including)
Red Hat Enterprise Linux 4RedHatfirefox-0:3.0.11-4.el4*
Red Hat Enterprise Linux 5RedHatfirefox-0:3.0.11-2.el5_3*
Red Hat Enterprise Linux 5RedHatxulrunner-0:1.9.0.11-3.el5_3*
Red Hat Enterprise Linux 5RedHatthunderbird-0:2.0.0.22-2.el5_3*
FirefoxUbuntudapper*
FirefoxUbuntuhardy*
Mozilla-thunderbirdUbuntudapper*
SeamonkeyUbuntudevel*
SeamonkeyUbuntuhardy*
SeamonkeyUbuntuintrepid*
SeamonkeyUbuntujaunty*
SeamonkeyUbuntukarmic*
SeamonkeyUbuntulucid*
SeamonkeyUbuntumaverick*
SeamonkeyUbuntunatty*
SeamonkeyUbuntuoneiric*
ThunderbirdUbuntudevel*
ThunderbirdUbuntuhardy*
ThunderbirdUbuntuintrepid*
ThunderbirdUbuntujaunty*
ThunderbirdUbuntukarmic*
ThunderbirdUbuntulucid*
ThunderbirdUbuntumaverick*
ThunderbirdUbuntunatty*
ThunderbirdUbuntuoneiric*
XulrunnerUbuntuhardy*
XulrunnerUbuntuintrepid*
XulrunnerUbuntujaunty*
XulrunnerUbuntukarmic*
Xulrunner-1.9Ubuntuhardy*
Xulrunner-1.9Ubuntuintrepid*
Xulrunner-1.9Ubuntujaunty*
Xulrunner-1.9.1Ubuntujaunty*
Xulrunner-1.9.1Ubuntukarmic*

Potential Mitigations

References