Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document provided in a non-200 CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
CVSS Details
- CVSS 3.1 Base Score: 7.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade thunderbirdUpgrade xulrunner-devel-unstableUpgrade xulrunnerUpgrade firefoxUpgrade xulrunner-devel | Dec 1, 2016 | Jun 12, 2009 |
| Freebsd | — | Upgrade linux-firefoxUpgrade linux-firefox-develUpgrade linux-seamonkeyUpgrade thunderbirdUpgrade seamonkeyUpgrade linux-thunderbirdUpgrade firefox | Dec 10, 2025 | Jun 12, 2009 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird.Upgrade www-client/seamonkey.Upgrade www-client/firefox-bin.Upgrade www-client/firefox.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/icecat.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade net-libs/xulrunner.Upgrade net-libs/xulrunner-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/mozilla-firefox.Upgrade mail-client/thunderbird-bin.Upgrade dev-libs/nss.Upgrade www-client/seamonkey-bin. | Oct 30, 2017 | Jun 12, 2009 |
| Mfsa2009 27 | — | Upgrade to Mozilla Firefox version 3.0.10 | Jun 14, 2012 | Jun 12, 2009 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.17 | Feb 3, 2012 | Jun 12, 2009 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 2.0.0.22 | Feb 22, 2012 | Jun 12, 2009 |
| Oracle_linux | — | Upgrade xulrunnerUpgrade xulrunner-devel-unstableUpgrade firefoxUpgrade xulrunner-devel | Oct 16, 2024 | Jun 12, 2009 |
| Suse | — | Upgrade mozilla-xulrunner190-translations-64bitUpgrade mozillafirefoxUpgrade mozilla-xulrunner190-translations-32bitUpgrade seamonkeyUpgrade seamonkey-venkmanUpgrade mozillafirefox-branding-upstreamUpgrade python-xpcom190Upgrade mozilla-xulrunner190-develUpgrade seamonkey-mailUpgrade mozillaUpgrade mozilla-dom-inspectorUpgrade mozilla-xulrunner190-64bitUpgrade mozilla-xulrunner190-gnomevfsUpgrade MozillaThunderbird-develUpgrade mozilla-mailUpgrade mozilla-xulrunner190-32bitUpgrade seamonkey-ircUpgrade mozilla-ircUpgrade mozilla-xulrunner190-gnomevfs-32bitUpgrade mozilla-develUpgrade seamonkey-dom-inspectorUpgrade MozillaFirefox-translationsUpgrade seamonkey-spellcheckerUpgrade MozillaThunderbird-translationsUpgrade mozilla-xulrunner190-translationsUpgrade mozilla-xulrunner190Upgrade mozilla-xulrunner190-gnomevfs-64bitUpgrade mozillathunderbirdUpgrade mozilla-venkman | Feb 17, 2015 | Jun 12, 2009 |
| Ubuntu | — | Upgrade thunderbirdUpgrade abrowserUpgrade xulrunner-1.9Upgrade firefox-3.0 | Nov 8, 2024 | Jun 12, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub