CVE-2009-2061: Critical severity Mozilla Firefox vulnerability
Mozilla Firefox before 3.0.10 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying this CONNECT response to specify a 302 redirect to an arbitrary https web site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2061?
CVE-2009-2061 has a severity rating that can lead to arbitrary web script execution by a man-in-the-middle, making it a significant security concern.
How do I fix CVE-2009-2061?
To mitigate CVE-2009-2061, upgrade to Mozilla Firefox version 3.0.10 or later, where this issue has been resolved.
What versions of Firefox are affected by CVE-2009-2061?
CVE-2009-2061 affects Mozilla Firefox versions prior to 3.0.10, including various earlier versions.
Can CVE-2009-2061 allow attackers to intercept traffic?
Yes, CVE-2009-2061 allows man-in-the-middle attackers to intercept and redirect HTTPS traffic due to improper handling of HTTP CONNECT responses.
Who is affected by CVE-2009-2061?
Users of vulnerable versions of Mozilla Firefox prior to 3.0.10 are at risk from CVE-2009-2061.