CVE-2009-3984: Medium severity mozilla seamonkey vulnerability
Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to spoof an SSL indicator for an http URL or a file URL by setting document.location to an https URL corresponding to a site that responds with a No Content (aka 204) status code and an empty body.
Other sources
Security researcher Jonathan Morgan reported that when a page loaded over an insecure protocol, such as http: or file:, sets its document.location to a https: URL which responds with a 204 status and empty response body, the insecure page will receive SSL indicators near the location bar, but will not have its page content modified in any way. This could lead to a user believing they were on a secure page when in fact they were not.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3984?
CVE-2009-3984 is classified as a moderate severity vulnerability affecting Mozilla Firefox and SeaMonkey.
How do I fix CVE-2009-3984?
To fix CVE-2009-3984, users should upgrade to Mozilla Firefox version 3.0.16 or 3.5.6 and SeaMonkey version 2.0.1 or later.
What does CVE-2009-3984 exploit?
CVE-2009-3984 exploits the ability for attackers to spoof SSL indicators by manipulating document location in certain conditions.
Which versions of Firefox are affected by CVE-2009-3984?
CVE-2009-3984 affects Firefox versions before 3.0.16 and 3.5.x before 3.5.6.
Is SeaMonkey vulnerable to CVE-2009-3984?
Yes, SeaMonkey versions before 2.0.1 are vulnerable to CVE-2009-3984.