Executive Summary

Informations
NameCVE-2009-1836First vendor Publication2009-06-12
VendorCveLast vendor Modification2010-08-21

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Cvss Base Score6.8Attack RangeNetwork
Cvss Impact Score6.4Attack ComplexityMedium
Cvss Expoit Score8.6AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document provided in a non-200 CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1836

CWE : Common Weakness Enumeration

idName
CWE-287Improper Authentication

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:11764
 
Oval ID: oval:org.mitre.oval:def:11764
Title: Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document provided in a non-200 CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
Description: Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document provided in a non-200 CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
Family: unix Class: vulnerability
Reference(s): CVE-2009-1836
Version: 5
Platform(s): Red Hat Enterprise Linux 4
CentOS Linux 4
Oracle Linux 4
Red Hat Enterprise Linux 5
CentOS Linux 5
Oracle Linux 5
Product(s):
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application103
Application32
Application70

Open Source Vulnerability Database (OSVDB)

idDescription
55160Mozilla Multiple Products Proxy Server CONNECT Response Manipulation SSL MiTM...

Internal Sources (Detail)

SourceUrl
BIDhttp://www.securityfocus.com/bid/35326
http://www.securityfocus.com/bid/35380
CONFIRMhttp://www.mozilla.org/security/announce/2009/mfsa2009-27.html
https://bugzilla.mozilla.org/show_bug.cgi?id=479880
https://bugzilla.redhat.com/show_bug.cgi?id=503578
DEBIANhttp://www.debian.org/security/2009/dsa-1820
http://www.debian.org/security/2009/dsa-1830
FEDORAhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00444.html
https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00504.html
https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00574.html
https://www.redhat.com/archives/fedora-package-announce/2009-June/msg00657.html
MANDRIVAhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:141
MISChttp://research.microsoft.com/apps/pubs/default.aspx?id=79323
http://research.microsoft.com/pubs/79323/pbp-final-with-update.pdf
OSVDBhttp://osvdb.org/55160
REDHAThttp://www.redhat.com/support/errata/RHSA-2009-1126.html
https://rhn.redhat.com/errata/RHSA-2009-1095.html
SECTRACKhttp://www.securitytracker.com/id?1022396
SECUNIAhttp://secunia.com/advisories/35331
http://secunia.com/advisories/35415
http://secunia.com/advisories/35431
http://secunia.com/advisories/35439
http://secunia.com/advisories/35440
http://secunia.com/advisories/35468
http://secunia.com/advisories/35536
http://secunia.com/advisories/35561
http://secunia.com/advisories/35602
http://secunia.com/advisories/35882
SLACKWAREhttp://slackware.com/security/viewer.php?l=slackware-security&y=2009&...
http://slackware.com/security/viewer.php?l=slackware-security&y=2009&...
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2009&...
SUNALERThttp://sunsolve.sun.com/search/document.do?assetkey=1-66-264308-1
UBUNTUhttp://www.ubuntu.com/usn/usn-782-1
VUPENhttp://www.vupen.com/english/advisories/2009/1572

Alert History

If you want to see full details history, please login or register.
0
DateInformations
2013-05-10 23:51:22
  • Multiple Updates