Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 709165 - (CVE-2011-0082) CVE-2011-0082 firefox: doesn't (re)validate certificates when loading HTTPS page
CVE-2011-0082 firefox: doesn't (re)validate certificates when loading HTTPS page
Status: CLOSED UPSTREAM
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
public=20110521,reported=20110522,sou...
: Security
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2011-05-30 18:38 EDT by Vincent Danen
Modified: 2012-12-17 17:53 EST (History)
5 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2011-08-25 09:54:20 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Mozilla Foundation 660749 None None None Never

  None (edit)
Description Vincent Danen 2011-05-30 18:38:43 EDT
A Debian bug report [1] indicated that Firefox 4.0.x handled the validation/revalidation of SSL certificates improperly.  If a user were to visit a site with an untrusted certificate, Firefox would correctly display the warning about the untrusted connection.  If a user were to confirm the security exception for a single session (not check off the "permanently store this exception"), then restart the browser and re-load the page, the contents of the page would be displayed from the Firefox cache.  Upon reloading the page, the security warning would appear, but incorrectly indicates that the site provides a valid, verified certificate and there is no way to confirm the exception.

This is not the case in Firefox 3.6.17 where when re-loading the browser and visiting the page, the untrusted connection warning comes up immediately, without showing the contents of the page, and allowing you to confirm the exception.

Steps to reproduce:

1) Visit a site with a self-signed certificate (such as https://kitenet.net/) and click "I Understand The Risks", click "Add Exception", uncheck "Permanently store this exception", click "Confirm Security Exception".  The site's contents will be displayed.

2) Exit the browser.

3) Start Firefox again and visit the page you visited in step 1.  The browser will show the contents of the page, even though its certificate should no longer be considered valid.

4) Refresh the page.  The untrusted connection warning will display again.  Click "I Understand The Risks", click "Add Exception".  Firefox will indicate that "This site provides valid, verified identification" and does not allow you to confirm the security exception.

[1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=627552
Comment 1 Huzaifa S. Sidhpurwala 2011-06-01 00:38:28 EDT
Reported upstream via:
https://bugzilla.mozilla.org/show_bug.cgi?id=660749
Comment 2 Josh Bressers 2011-08-25 09:54:20 EDT
There's nothing we can do about this until upstream acts. The issue is quite minor, so I'm closing this UPSTREAM. We'll reopen the bug once it gets fixed.

Note You need to log in before you can comment on or make changes to this bug.