FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-1836

This CVE name corresponds to:

Entered Topic
2009-06-12 mozilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-1836
Phase Assigned(20090529)

Description

Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document provided in a non-200 CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.

References

Source Reference
MISC http://research.microsoft.com/apps/pubs/default.aspx?id=79323
MISC http://research.microsoft.com/pubs/79323/pbp-final-with-update.pdf
CONFIRM http://www.mozilla.org/security/announce/2009/mfsa2009-27.html
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=479880
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=503578
DEBIAN DSA-1820
DEBIAN DSA-1830
FEDORA FEDORA-2009-6366
FEDORA FEDORA-2009-6411
FEDORA FEDORA-2009-7567
FEDORA FEDORA-2009-7614
MANDRIVA MDVSA-2009:141
REDHAT RHSA-2009:1095
REDHAT RHSA-2009:1126
SLACKWARE SSA:2009-167-01
SLACKWARE SSA:2009-176-01
SLACKWARE SSA:2009-178-01
SUNALERT 264308
UBUNTU USN-782-1
BID 35326
BID 35380
OSVDB 55160
OVAL oval:org.mitre.oval:def:11764
SECTRACK 1022396
SECUNIA 35331
SECUNIA 35431
SECUNIA 35439
SECUNIA 35440
SECUNIA 35468
SECUNIA 35536
SECUNIA 35415
SECUNIA 35561
SECUNIA 35602
SECUNIA 35882
VUPEN ADV-2009-1572