CVE Vulnerabilities

CVE-2009-1836

Improper Authentication

Published: Jun 12, 2009 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document provided in a non-200 CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an SSL tampering attack.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Seamonkey Mozilla 1.1.10 1.1.10
Firefox Mozilla 0.1 0.1
Thunderbird Mozilla 1.5.0.7 1.5.0.7
Firefox Mozilla 0.9_rc 0.9_rc
Thunderbird Mozilla 0.6 0.6
Seamonkey Mozilla 1.0.3 1.0.3
Firefox Mozilla 0.8 0.8
Firefox Mozilla 2.0.0.12 2.0.0.12
Thunderbird Mozilla 0.7.2 0.7.2
Firefox Mozilla 1.5 1.5
Firefox Mozilla 2.0_.7 2.0_.7
Thunderbird Mozilla 2.0.0.4 2.0.0.4
Seamonkey Mozilla 1.1.8 1.1.8
Seamonkey Mozilla * 1.1.16
Firefox Mozilla 3.0.7 3.0.7
Firefox Mozilla 1.5.2 1.5.2
Seamonkey Mozilla 1.0.1 1.0.1
Seamonkey Mozilla 1.1.7 1.1.7
Thunderbird Mozilla 2.0.0.6 2.0.0.6
Firefox Mozilla 3.0.9 3.0.9
Seamonkey Mozilla 1.0.6 1.0.6
Firefox Mozilla 1.5.0.6 1.5.0.6
Firefox Mozilla 1.8 1.8
Seamonkey Mozilla 1.0.9 1.0.9
Thunderbird Mozilla 0.3 0.3
Seamonkey Mozilla 1.1.3 1.1.3
Firefox Mozilla 2.0.0.2 2.0.0.2
Firefox Mozilla 1.5.0.10 1.5.0.10
Firefox Mozilla 1.5.0.3 1.5.0.3
Thunderbird Mozilla 0.2 0.2
Seamonkey Mozilla 1.0 1.0
Firefox Mozilla 3.0.8 3.0.8
Thunderbird Mozilla 2.0_.5 2.0_.5
Thunderbird Mozilla 1.0.7 1.0.7
Firefox Mozilla 1.5.0.11 1.5.0.11
Thunderbird Mozilla 2.0.0.18 2.0.0.18
Firefox Mozilla 1.4.1 1.4.1
Seamonkey Mozilla 1.0.99 1.0.99
Thunderbird Mozilla 2.0.0.9 2.0.0.9
Firefox Mozilla 1.5.4 1.5.4
Seamonkey Mozilla 1.1.5 1.1.5
Firefox Mozilla 1.0.2 1.0.2
Seamonkey Mozilla 1.0 1.0
Thunderbird Mozilla 2.0_.12 2.0_.12
Thunderbird Mozilla 2.0.0.15 2.0.0.15
Firefox Mozilla 3.0.4 3.0.4
Firefox Mozilla 1.5 1.5
Seamonkey Mozilla 1.1 1.1
Thunderbird Mozilla 2.0.0.16 2.0.0.16
Firefox Mozilla 2.0_8 2.0_8
Thunderbird Mozilla 2.0.0.8 2.0.0.8
Thunderbird Mozilla 2.0.0.7 2.0.0.7
Firefox Mozilla 2.0_.9 2.0_.9
Firefox Mozilla 3.0.5 3.0.5
Seamonkey Mozilla 1.0 1.0
Thunderbird Mozilla 1.7.1 1.7.1
Thunderbird Mozilla 2.0_8 2.0_8
Firefox Mozilla 1.5 1.5
Thunderbird Mozilla 1.5.0.3 1.5.0.3
Firefox Mozilla 0.9.1 0.9.1
Thunderbird Mozilla 1.5.0.10 1.5.0.10
Thunderbird Mozilla 1.5.0.5 1.5.0.5
Firefox Mozilla 1.0.4 1.0.4
Firefox Mozilla 2.0.0.7 2.0.0.7
Firefox Mozilla 1.0.7 1.0.7
Thunderbird Mozilla 1.5.0.6 1.5.0.6
Seamonkey Mozilla 1.1.12 1.1.12
Seamonkey Mozilla 1.1 1.1
Firefox Mozilla 2.0.0.9 2.0.0.9
Firefox Mozilla 0.10.1 0.10.1
Firefox Mozilla 2.0_.1 2.0_.1
Thunderbird Mozilla 1.0 1.0
Thunderbird Mozilla 2.0.0.3 2.0.0.3
Firefox Mozilla 0.9 0.9
Thunderbird Mozilla 1.0.1 1.0.1
Firefox Mozilla 2.0.0.16 2.0.0.16
Thunderbird Mozilla 1.5 1.5
Firefox Mozilla 3.0 3.0
Firefox Mozilla 1.5.6 1.5.6
Thunderbird Mozilla 2.0.0.2 2.0.0.2
Firefox Mozilla 2.0.0.17 2.0.0.17
Firefox Mozilla 0.7 0.7
Firefox Mozilla 2.0.0.15 2.0.0.15
Seamonkey Mozilla 1.0 1.0
Firefox Mozilla 0.2 0.2
Seamonkey Mozilla 1.0.8 1.0.8
Thunderbird Mozilla 1.0.2 1.0.2
Firefox Mozilla 0.3 0.3
Thunderbird Mozilla 2.0.0.0 2.0.0.0
Thunderbird Mozilla 1.5.0.13 1.5.0.13
Seamonkey Mozilla 1.1.11 1.1.11
Firefox Mozilla 2.0_.10 2.0_.10
Firefox Mozilla 1.0 1.0
Firefox Mozilla 3.0.3 3.0.3
Seamonkey Mozilla 1.1 1.1
Seamonkey Mozilla 1.1.1 1.1.1
Firefox Mozilla 1.5.0.7 1.5.0.7
Thunderbird Mozilla 2.0.0.12 2.0.0.12
Firefox Mozilla 2.0 2.0
Thunderbird Mozilla 1.5 1.5
Firefox Mozilla 1.0.1 1.0.1
Thunderbird Mozilla 1.5.0.2 1.5.0.2
Seamonkey Mozilla 1.1.5 1.1.5
Firefox Mozilla 2.0 2.0
Firefox Mozilla 2.0.0.14 2.0.0.14
Firefox Mozilla 0.6 0.6
Thunderbird Mozilla 2.0.0.13 2.0.0.13
Firefox Mozilla * 3.0.10
Firefox Mozilla 0.7.1 0.7.1
Seamonkey Mozilla 1.1.15 1.1.15
Thunderbird Mozilla 2.0_.9 2.0_.9
Firefox Mozilla 3.0.6 3.0.6
Thunderbird Mozilla 1.5.0.8 1.5.0.8
Thunderbird Mozilla 2.0.0.14 2.0.0.14
Firefox Mozilla 1.5.0.8 1.5.0.8
Firefox Mozilla 2.0_.5 2.0_.5
Firefox Mozilla 1.0.6 1.0.6
Thunderbird Mozilla 0.5 0.5
Thunderbird Mozilla 1.0.4 1.0.4
Firefox Mozilla 2.0.0.3 2.0.0.3
Thunderbird Mozilla 1.5.2 1.5.2
Firefox Mozilla 1.5.0.9 1.5.0.9
Thunderbird Mozilla 2.0.0.17 2.0.0.17
Firefox Mozilla 1.5.0.5 1.5.0.5
Firefox Mozilla 1.5.7 1.5.7
Firefox Mozilla 1.5.0.12 1.5.0.12
Thunderbird Mozilla * 2.0.0.19
Thunderbird Mozilla 1.5.0.9 1.5.0.9
Thunderbird Mozilla 1.5.0.11 1.5.0.11
Thunderbird Mozilla 0.9 0.9
Thunderbird Mozilla 1.0.3 1.0.3
Firefox Mozilla 2.0.0.6 2.0.0.6
Seamonkey Mozilla 1.1.6 1.1.6
Thunderbird Mozilla 2.0.0.11 2.0.0.11
Thunderbird Mozilla 1.5.0.12 1.5.0.12
Thunderbird Mozilla 2.0_.13 2.0_.13
Firefox Mozilla 3.0 3.0
Firefox Mozilla 2.0.0.11 2.0.0.11
Firefox Mozilla 1.5.0.2 1.5.0.2
Firefox Mozilla 1.0.3 1.0.3
Firefox Mozilla 3.0.1 3.0.1
Firefox Mozilla 2.0.0.4 2.0.0.4
Firefox Mozilla 0.5 0.5
Firefox Mozilla 0.6.1 0.6.1
Firefox Mozilla 1.5.1 1.5.1
Thunderbird Mozilla 2.0_.14 2.0_.14
Thunderbird Mozilla 0.7.3 0.7.3
Firefox Mozilla 2.0.0.21 2.0.0.21
Firefox Mozilla 0.9.3 0.9.3
Seamonkey Mozilla 1.0 1.0
Firefox Mozilla 2.0.0.13 2.0.0.13
Firefox Mozilla 2.0.0.18 2.0.0.18
Thunderbird Mozilla 0.4 0.4
Seamonkey Mozilla 1.0 1.0
Thunderbird Mozilla 1.5.1 1.5.1
Thunderbird Mozilla 0.7 0.7
Thunderbird Mozilla 1.5.0.14 1.5.0.14
Firefox Mozilla 2.0 2.0
Firefox Mozilla 2.0.0.1 2.0.0.1
Thunderbird Mozilla 1.0.6 1.0.6
Firefox Mozilla 3.0.2 3.0.2
Thunderbird Mozilla 1.0.5 1.0.5
Firefox Mozilla 2.0_.6 2.0_.6
Firefox Mozilla 2.0_.4 2.0_.4
Thunderbird Mozilla 2.0.0.5 2.0.0.5
Thunderbird Mozilla 1.7.3 1.7.3
Seamonkey Mozilla 1.0.4 1.0.4
Firefox Mozilla 1.5.5 1.5.5
Firefox Mozilla 0.9.2 0.9.2
Firefox Mozilla 1.0 1.0
Thunderbird Mozilla 2.0.0.1 2.0.0.1
Firefox Mozilla 2.0 2.0
Seamonkey Mozilla 1.1.9 1.1.9
Seamonkey Mozilla 1.1.13 1.1.13
Firefox Mozilla 3.0beta5 3.0beta5
Firefox Mozilla 2.0.0.20 2.0.0.20
Thunderbird Mozilla 1.5.0.1 1.5.0.1
Firefox Mozilla 2.0.0.8 2.0.0.8
Thunderbird Mozilla 2.0_.4 2.0_.4
Thunderbird Mozilla 1.0.8 1.0.8
Thunderbird Mozilla 0.1 0.1
Firefox Mozilla 3.0 3.0
Firefox Mozilla 0.9 0.9
Firefox Mozilla 2.0.0.19 2.0.0.19
Firefox Mozilla 1.5.8 1.5.8
Firefox Mozilla 1.5.3 1.5.3
Firefox Mozilla 0.4 0.4
Thunderbird Mozilla 0.7.1 0.7.1
Thunderbird Mozilla 1.0.5 1.0.5
Thunderbird Mozilla 0.8 0.8
Firefox Mozilla 1.5.0.4 1.5.0.4
Firefox Mozilla 1.5.0.1 1.5.0.1
Firefox Mozilla 0.10 0.10
Thunderbird Mozilla 2.0_.6 2.0_.6
Firefox Mozilla 1.0.5 1.0.5
Firefox Mozilla 2.0.0.5 2.0.0.5
Firefox Mozilla 2.0.0.10 2.0.0.10
Firefox Mozilla 2.0 2.0
Firefox Mozilla 3.0 3.0
Firefox Mozilla 1.0.6 1.0.6
Thunderbird Mozilla 1.5.0.4 1.5.0.4
Firefox Mozilla 1.0.8 1.0.8

Potential Mitigations

References