Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to spoof an SSL indicator for an http URL or a file URL by setting document.location to an https URL corresponding to a site that responds with a No Content (aka 204) status code and an empty body.

Project Subscriptions

Vendors Products
Mozilla Subscribe
Firefox Subscribe
Seamonkey Subscribe
Thunderbird Subscribe
Enterprise Linux Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-1956-1 New xulrunner packages fix several vulnerabilities
EUVD EUVD EUVD-2009-3955 Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to spoof an SSL indicator for an http URL or a file URL by setting document.location to an https URL corresponding to a site that responds with a No Content (aka 204) status code and an empty body.
Ubuntu USN Ubuntu USN USN-873-1 Firefox 3.0 and Xulrunner 1.9 vulnerabilities
Ubuntu USN Ubuntu USN USN-874-1 Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://secunia.com/advisories/37699 cve-icon cve-icon
http://secunia.com/advisories/37703 cve-icon cve-icon
http://secunia.com/advisories/37704 cve-icon cve-icon
http://secunia.com/advisories/37785 cve-icon cve-icon
http://secunia.com/advisories/37813 cve-icon cve-icon
http://secunia.com/advisories/37856 cve-icon cve-icon
http://secunia.com/advisories/37881 cve-icon cve-icon
http://securitytracker.com/id?1023342 cve-icon cve-icon
http://securitytracker.com/id?1023343 cve-icon cve-icon
http://www.debian.org/security/2009/dsa-1956 cve-icon cve-icon
http://www.mozilla.org/security/announce/2009/mfsa2009-69.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2009_63_firefox.html cve-icon cve-icon
http://www.securityfocus.com/bid/37349 cve-icon cve-icon
http://www.securityfocus.com/bid/37367 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-873-1 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-874-1 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/3547 cve-icon cve-icon
https://bugzilla.mozilla.org/show_bug.cgi?id=521461 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=546722 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/54806 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2009-3984 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8379 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9791 cve-icon cve-icon
https://rhn.redhat.com/errata/RHSA-2009-1673.html cve-icon cve-icon
https://rhn.redhat.com/errata/RHSA-2009-1674.html cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2009-3984 cve-icon
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00995.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01034.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01041.html cve-icon cve-icon
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T06:45:50.789Z

Reserved: 2009-11-19T00:00:00

Link: CVE-2009-3984

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2009-12-17T17:30:00.500

Modified: 2025-04-09T00:30:58.490

Link: CVE-2009-3984

cve-icon Redhat

Severity : Moderate

Publid Date: 2009-12-15T00:00:00Z

Links: CVE-2009-3984 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses