MEDIUM
Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack
Published Jun 15, 2009
5.8
MEDIUMCVSS 2.0
EPSS 3.03%
Description
Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
Affected products
No data.
OR
- 5.0
- 5.0
- 5.22
- 6.0
- 6.0
- 3.0
- 3.0.1
- 3.0.2
- 3.1
- 3.2
- 4.0
- 4.0.1
- 4.0.1
- 4.0.1
- 4.01
- 4.1
- 4.01
- 4.5
- 4.40.308
- 4.40.520
- 4.70.1155
- 4.70.1158
- 4.70.1215
- 4.70.1300
- 4.71.544
- 4.71.1008.3
- 4.71.1712.6
- 4.72.2106.8
- 4.72.3110.8
- 4.72.3612.1713
- 5
- 5.0
- 5.0.1
- 5.0.1
- 5.0.1
- 5.0.1
- 5.0.1
- 5.00.0518.10
- 5.00.0910.1309
- 5.00.2014.0216
- 5.00.2314.1003
- 5.00.2614.3500
- 5.00.2919.800
- 5.00.2919.3800
- 5.00.2919.6307
- 5.00.2920.0000
- 5.00.3103.1000
- 5.00.3105.0106
- 5.00.3314.2101
- 5.00.3315.1000
- 5.00.3502.1000
- 5.00.3700.1000
- 5.01
- 5.1
- 5.01
- 5.01
- 5.01
- 5.01
- 5.2.3
- 5.5
- 5.5
- 5.5
- 5.5
- 5.50.3825.1300
- 5.50.4030.2400
- 5.50.4134.0600
- 5.50.4308.2900
- 5.50.4522.1800
- 5.50.4807.2300
- 6
- 6
- 6.0
- 6.00.2462.0000
- 6.00.2479.0006
- 6.0.2600
- 6.0.2800
- 6.0.2800.1106
- 6.00.2800.1106
- 6.0.2900
- 6.0.2900.2180
- 6.00.2900.2180
- 6.00.3663.0000
- 6.00.3790.0000
- 6.00.3790.1830
- 6.00.3790.3959
- 7
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0.5730.11
- 7.00.5730.1100
- 7.00.6000.16386
- 7.00.6000.16441
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://research.microsoft.com/apps/pubs/default.aspx?id=79323 x_refsource_MISC
- http://research.microsoft.com/pubs/79323/pbp-final-with-update.pdf x_refsource_MISCExploit
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-2053 Advisory
| Link | Providers | Tags |
|---|---|---|
| http://research.microsoft.com/apps/pubs/default.aspx?id=79323 | x_refsource_MISC | |
| http://research.microsoft.com/pubs/79323/pbp-final-with-update.pdf | x_refsource_MISCExploit | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-2053 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 15, 2009
Updated Sep 17, 2024
Reserved Jun 15, 2009
Link CVE-2009-2057
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-2053 Assigner mitre
Published Jun 15, 2009
Updated Sep 17, 2024
Exploited since n/a
Link EUVD-2009-2053