HIGH
Mozilla Firefox before 3.0.10 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying this CONNECT response to specify a 302 redirect to an arbitrary https web site
Published Jun 15, 2009
9.3
HIGHCVSS 2.0
EPSS 1.24%
Description
Mozilla Firefox before 3.0.10 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying this CONNECT response to specify a 302 redirect to an arbitrary https web site.
Affected products
No data.
OR
- ≤ 3.0.9
- 0.1
- 0.2
- 0.3
- 0.4
- 0.5
- 0.6
- 0.6.1
- 0.7
- 0.7.1
- 0.8
- 0.9
- 0.9
- 0.9.1
- 0.9.2
- 0.9.3
- 0.9_rc
- 0.10
- 0.10.1
- 1.0
- 1.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.0.5
- 1.0.6
- 1.0.7
- 1.0.8
- 1.4.1
- 1.5
- 1.5
- 1.5
- 1.5.0.1
- 1.5.0.2
- 1.5.0.3
- 1.5.0.4
- 1.5.0.5
- 1.5.0.6
- 1.5.0.7
- 1.5.0.8
- 1.5.0.9
- 1.5.0.10
- 1.5.0.11
- 1.5.0.12
- 1.5.1
- 1.5.2
- 1.5.3
- 1.5.4
- 1.5.5
- 1.5.6
- 1.5.7
- 1.5.8
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0.0.1
- 2.0.0.3
- 2.0.0.4
- 2.0.0.5
- 2.0.0.6
- 2.0.0.7
- 2.0.0.9
- 2.0.0.10
- 2.0.0.11
- 2.0.0.12
- 2.0.0.13
- 2.0.0.14
- 2.0.0.15
- 2.0.0.17
- 2.0.0.18
- 2.0.0.19
- 2.0.0.20
- 2.0.0.21
- 2.0_.1
- 2.0_.4
- 2.0_.5
- 2.0_.6
- 2.0_.9
- 3.0
- 3.0.1
- 3.0.2
- 3.0.4
- 3.0.6
- 3.0.7
- 3.0.8
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://research.microsoft.com/apps/pubs/default.aspx?id=79323 x_refsource_MISC
- http://research.microsoft.com/pubs/79323/pbp-final-with-update.pdf x_refsource_MISCExploit
- http://www.securityfocus.com/bid/35412 vdb-entryx_refsource_BID
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51203 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://research.microsoft.com/apps/pubs/default.aspx?id=79323 | x_refsource_MISC | |
| http://research.microsoft.com/pubs/79323/pbp-final-with-update.pdf | x_refsource_MISCExploit | |
| http://www.securityfocus.com/bid/35412 | vdb-entryx_refsource_BID | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/51203 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 15, 2009
Updated Aug 7, 2024
Reserved Jun 15, 2009
Link CVE-2009-2061
CISA Vulnrichment
Updated n/a