CVE Vulnerabilities

CVE-2009-1836

Improper Authentication

Published: Jun 12, 2009 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
1.8 MODERATE
AV:A/AC:H/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu

Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document provided in a non-200 CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an SSL tampering attack.

Weakness

When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla 0.1 0.1
Firefox Mozilla 0.2 0.2
Firefox Mozilla 0.3 0.3
Firefox Mozilla 0.4 0.4
Firefox Mozilla 0.5 0.5
Firefox Mozilla 0.6 0.6
Firefox Mozilla 0.6.1 0.6.1
Firefox Mozilla 0.7 0.7
Firefox Mozilla 0.7.1 0.7.1
Firefox Mozilla 0.8 0.8
Firefox Mozilla 0.9 0.9
Firefox Mozilla 0.9 0.9
Firefox Mozilla 0.9.1 0.9.1
Firefox Mozilla 0.9.2 0.9.2
Firefox Mozilla 0.9.3 0.9.3
Firefox Mozilla 0.9_rc 0.9_rc
Firefox Mozilla 0.10 0.10
Firefox Mozilla 0.10.1 0.10.1
Firefox Mozilla 1.0 1.0
Firefox Mozilla 1.0 1.0
Firefox Mozilla 1.0.1 1.0.1
Firefox Mozilla 1.0.2 1.0.2
Firefox Mozilla 1.0.3 1.0.3
Firefox Mozilla 1.0.4 1.0.4
Firefox Mozilla 1.0.5 1.0.5
Firefox Mozilla 1.0.6 1.0.6
Firefox Mozilla 1.0.6 1.0.6
Firefox Mozilla 1.0.7 1.0.7
Firefox Mozilla 1.0.8 1.0.8
Firefox Mozilla 1.4.1 1.4.1
Firefox Mozilla 1.5 1.5
Firefox Mozilla 1.5 1.5
Firefox Mozilla 1.5 1.5
Firefox Mozilla 1.5.0.1 1.5.0.1
Firefox Mozilla 1.5.0.2 1.5.0.2
Firefox Mozilla 1.5.0.3 1.5.0.3
Firefox Mozilla 1.5.0.4 1.5.0.4
Firefox Mozilla 1.5.0.5 1.5.0.5
Firefox Mozilla 1.5.0.6 1.5.0.6
Firefox Mozilla 1.5.0.7 1.5.0.7
Firefox Mozilla 1.5.0.8 1.5.0.8
Firefox Mozilla 1.5.0.9 1.5.0.9
Firefox Mozilla 1.5.0.10 1.5.0.10
Firefox Mozilla 1.5.0.11 1.5.0.11
Firefox Mozilla 1.5.0.12 1.5.0.12
Firefox Mozilla 1.5.1 1.5.1
Firefox Mozilla 1.5.2 1.5.2
Firefox Mozilla 1.5.3 1.5.3
Firefox Mozilla 1.5.4 1.5.4
Firefox Mozilla 1.5.5 1.5.5
Firefox Mozilla 1.5.6 1.5.6
Firefox Mozilla 1.5.7 1.5.7
Firefox Mozilla 1.5.8 1.5.8
Firefox Mozilla 1.8 1.8
Firefox Mozilla 2.0 2.0
Firefox Mozilla 2.0 2.0
Firefox Mozilla 2.0 2.0
Firefox Mozilla 2.0 2.0
Firefox Mozilla 2.0 2.0
Firefox Mozilla 2.0.0.1 2.0.0.1
Firefox Mozilla 2.0.0.2 2.0.0.2
Firefox Mozilla 2.0.0.3 2.0.0.3
Firefox Mozilla 2.0.0.4 2.0.0.4
Firefox Mozilla 2.0.0.5 2.0.0.5
Firefox Mozilla 2.0.0.6 2.0.0.6
Firefox Mozilla 2.0.0.7 2.0.0.7
Firefox Mozilla 2.0.0.8 2.0.0.8
Firefox Mozilla 2.0.0.9 2.0.0.9
Firefox Mozilla 2.0.0.10 2.0.0.10
Firefox Mozilla 2.0.0.11 2.0.0.11
Firefox Mozilla 2.0.0.12 2.0.0.12
Firefox Mozilla 2.0.0.13 2.0.0.13
Firefox Mozilla 2.0.0.14 2.0.0.14
Firefox Mozilla 2.0.0.15 2.0.0.15
Firefox Mozilla 2.0.0.16 2.0.0.16
Firefox Mozilla 2.0.0.17 2.0.0.17
Firefox Mozilla 2.0.0.18 2.0.0.18
Firefox Mozilla 2.0.0.19 2.0.0.19
Firefox Mozilla 2.0.0.20 2.0.0.20
Firefox Mozilla 2.0.0.21 2.0.0.21
Firefox Mozilla 2.0_.1 2.0_.1
Firefox Mozilla 2.0_.4 2.0_.4
Firefox Mozilla 2.0_.5 2.0_.5
Firefox Mozilla 2.0_.6 2.0_.6
Firefox Mozilla 2.0_.7 2.0_.7
Firefox Mozilla 2.0_.9 2.0_.9
Firefox Mozilla 2.0_.10 2.0_.10
Firefox Mozilla 2.0_8 2.0_8
Firefox Mozilla 3.0 3.0
Firefox Mozilla 3.0 3.0
Firefox Mozilla 3.0 3.0
Firefox Mozilla 3.0 3.0
Firefox Mozilla 3.0.1 3.0.1
Firefox Mozilla 3.0.2 3.0.2
Firefox Mozilla 3.0.3 3.0.3
Firefox Mozilla 3.0.4 3.0.4
Firefox Mozilla 3.0.5 3.0.5
Firefox Mozilla 3.0.6 3.0.6
Firefox Mozilla 3.0.7 3.0.7
Firefox Mozilla 3.0.8 3.0.8
Firefox Mozilla 3.0.9 3.0.9
Firefox Mozilla * 3.0.10
Firefox Mozilla 3.0beta5 3.0beta5
Seamonkey Mozilla 1.0 1.0
Seamonkey Mozilla 1.0 1.0
Seamonkey Mozilla 1.0 1.0
Seamonkey Mozilla 1.0 1.0
Seamonkey Mozilla 1.0 1.0
Seamonkey Mozilla 1.0 1.0
Seamonkey Mozilla 1.0.1 1.0.1
Seamonkey Mozilla 1.0.3 1.0.3
Seamonkey Mozilla 1.0.4 1.0.4
Seamonkey Mozilla 1.0.6 1.0.6
Seamonkey Mozilla 1.0.8 1.0.8
Seamonkey Mozilla 1.0.9 1.0.9
Seamonkey Mozilla 1.0.99 1.0.99
Seamonkey Mozilla 1.1 1.1
Seamonkey Mozilla 1.1 1.1
Seamonkey Mozilla 1.1 1.1
Seamonkey Mozilla 1.1.1 1.1.1
Seamonkey Mozilla 1.1.3 1.1.3
Seamonkey Mozilla 1.1.5 1.1.5
Seamonkey Mozilla 1.1.5 1.1.5
Seamonkey Mozilla 1.1.6 1.1.6
Seamonkey Mozilla 1.1.7 1.1.7
Seamonkey Mozilla 1.1.8 1.1.8
Seamonkey Mozilla 1.1.9 1.1.9
Seamonkey Mozilla 1.1.10 1.1.10
Seamonkey Mozilla 1.1.11 1.1.11
Seamonkey Mozilla 1.1.12 1.1.12
Seamonkey Mozilla 1.1.13 1.1.13
Seamonkey Mozilla 1.1.15 1.1.15
Seamonkey Mozilla * 1.1.16
Thunderbird Mozilla 0.1 0.1
Thunderbird Mozilla 0.2 0.2
Thunderbird Mozilla 0.3 0.3
Thunderbird Mozilla 0.4 0.4
Thunderbird Mozilla 0.5 0.5
Thunderbird Mozilla 0.6 0.6
Thunderbird Mozilla 0.7 0.7
Thunderbird Mozilla 0.7.1 0.7.1
Thunderbird Mozilla 0.7.2 0.7.2
Thunderbird Mozilla 0.7.3 0.7.3
Thunderbird Mozilla 0.8 0.8
Thunderbird Mozilla 0.9 0.9
Thunderbird Mozilla 1.0 1.0
Thunderbird Mozilla 1.0.1 1.0.1
Thunderbird Mozilla 1.0.2 1.0.2
Thunderbird Mozilla 1.0.3 1.0.3
Thunderbird Mozilla 1.0.4 1.0.4
Thunderbird Mozilla 1.0.5 1.0.5
Thunderbird Mozilla 1.0.5 1.0.5
Thunderbird Mozilla 1.0.6 1.0.6
Thunderbird Mozilla 1.0.7 1.0.7
Thunderbird Mozilla 1.0.8 1.0.8
Thunderbird Mozilla 1.5 1.5
Thunderbird Mozilla 1.5 1.5
Thunderbird Mozilla 1.5.0.1 1.5.0.1
Thunderbird Mozilla 1.5.0.2 1.5.0.2
Thunderbird Mozilla 1.5.0.3 1.5.0.3
Thunderbird Mozilla 1.5.0.4 1.5.0.4
Thunderbird Mozilla 1.5.0.5 1.5.0.5
Thunderbird Mozilla 1.5.0.6 1.5.0.6
Thunderbird Mozilla 1.5.0.7 1.5.0.7
Thunderbird Mozilla 1.5.0.8 1.5.0.8
Thunderbird Mozilla 1.5.0.9 1.5.0.9
Thunderbird Mozilla 1.5.0.10 1.5.0.10
Thunderbird Mozilla 1.5.0.11 1.5.0.11
Thunderbird Mozilla 1.5.0.12 1.5.0.12
Thunderbird Mozilla 1.5.0.13 1.5.0.13
Thunderbird Mozilla 1.5.0.14 1.5.0.14
Thunderbird Mozilla 1.5.1 1.5.1
Thunderbird Mozilla 1.5.2 1.5.2
Thunderbird Mozilla 1.7.1 1.7.1
Thunderbird Mozilla 1.7.3 1.7.3
Thunderbird Mozilla 2.0.0.0 2.0.0.0
Thunderbird Mozilla 2.0.0.1 2.0.0.1
Thunderbird Mozilla 2.0.0.2 2.0.0.2
Thunderbird Mozilla 2.0.0.3 2.0.0.3
Thunderbird Mozilla 2.0.0.4 2.0.0.4
Thunderbird Mozilla 2.0.0.5 2.0.0.5
Thunderbird Mozilla 2.0.0.6 2.0.0.6
Thunderbird Mozilla 2.0.0.7 2.0.0.7
Thunderbird Mozilla 2.0.0.8 2.0.0.8
Thunderbird Mozilla 2.0.0.9 2.0.0.9
Thunderbird Mozilla 2.0.0.11 2.0.0.11
Thunderbird Mozilla 2.0.0.12 2.0.0.12
Thunderbird Mozilla 2.0.0.13 2.0.0.13
Thunderbird Mozilla 2.0.0.14 2.0.0.14
Thunderbird Mozilla 2.0.0.15 2.0.0.15
Thunderbird Mozilla 2.0.0.16 2.0.0.16
Thunderbird Mozilla 2.0.0.17 2.0.0.17
Thunderbird Mozilla 2.0.0.18 2.0.0.18
Thunderbird Mozilla * 2.0.0.19
Thunderbird Mozilla 2.0_.4 2.0_.4
Thunderbird Mozilla 2.0_.5 2.0_.5
Thunderbird Mozilla 2.0_.6 2.0_.6
Thunderbird Mozilla 2.0_.9 2.0_.9
Thunderbird Mozilla 2.0_.12 2.0_.12
Thunderbird Mozilla 2.0_.13 2.0_.13
Thunderbird Mozilla 2.0_.14 2.0_.14
Thunderbird Mozilla 2.0_8 2.0_8
Red Hat Enterprise Linux 4 RedHat firefox-0:3.0.11-4.el4 *
Red Hat Enterprise Linux 5 RedHat firefox-0:3.0.11-2.el5_3 *
Red Hat Enterprise Linux 5 RedHat xulrunner-0:1.9.0.11-3.el5_3 *
Red Hat Enterprise Linux 5 RedHat thunderbird-0:2.0.0.22-2.el5_3 *
Firefox Ubuntu dapper *
Firefox Ubuntu hardy *
Mozilla-thunderbird Ubuntu dapper *
Seamonkey Ubuntu devel *
Seamonkey Ubuntu hardy *
Seamonkey Ubuntu intrepid *
Seamonkey Ubuntu jaunty *
Seamonkey Ubuntu karmic *
Seamonkey Ubuntu lucid *
Seamonkey Ubuntu maverick *
Seamonkey Ubuntu natty *
Seamonkey Ubuntu oneiric *
Thunderbird Ubuntu devel *
Thunderbird Ubuntu hardy *
Thunderbird Ubuntu intrepid *
Thunderbird Ubuntu jaunty *
Thunderbird Ubuntu karmic *
Thunderbird Ubuntu lucid *
Thunderbird Ubuntu maverick *
Thunderbird Ubuntu natty *
Thunderbird Ubuntu oneiric *
Xulrunner Ubuntu hardy *
Xulrunner Ubuntu intrepid *
Xulrunner Ubuntu jaunty *
Xulrunner Ubuntu karmic *
Xulrunner-1.9 Ubuntu hardy *
Xulrunner-1.9 Ubuntu intrepid *
Xulrunner-1.9 Ubuntu jaunty *
Xulrunner-1.9.1 Ubuntu jaunty *
Xulrunner-1.9.1 Ubuntu karmic *

Potential Mitigations

References