Bug 709165 (CVE-2011-0082) - CVE-2011-0082 firefox: doesn't (re)validate certificates when loading HTTPS page
Summary: CVE-2011-0082 firefox: doesn't (re)validate certificates when loading HTTPS page
Keywords:
Status: CLOSED UPSTREAM
Alias: CVE-2011-0082
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-05-30 22:38 UTC by Vincent Danen
Modified: 2019-09-29 12:45 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2011-08-25 13:54:20 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Mozilla Foundation 660749 0 None None None Never

Description Vincent Danen 2011-05-30 22:38:43 UTC
A Debian bug report [1] indicated that Firefox 4.0.x handled the validation/revalidation of SSL certificates improperly.  If a user were to visit a site with an untrusted certificate, Firefox would correctly display the warning about the untrusted connection.  If a user were to confirm the security exception for a single session (not check off the "permanently store this exception"), then restart the browser and re-load the page, the contents of the page would be displayed from the Firefox cache.  Upon reloading the page, the security warning would appear, but incorrectly indicates that the site provides a valid, verified certificate and there is no way to confirm the exception.

This is not the case in Firefox 3.6.17 where when re-loading the browser and visiting the page, the untrusted connection warning comes up immediately, without showing the contents of the page, and allowing you to confirm the exception.

Steps to reproduce:

1) Visit a site with a self-signed certificate (such as https://kitenet.net/) and click "I Understand The Risks", click "Add Exception", uncheck "Permanently store this exception", click "Confirm Security Exception".  The site's contents will be displayed.

2) Exit the browser.

3) Start Firefox again and visit the page you visited in step 1.  The browser will show the contents of the page, even though its certificate should no longer be considered valid.

4) Refresh the page.  The untrusted connection warning will display again.  Click "I Understand The Risks", click "Add Exception".  Firefox will indicate that "This site provides valid, verified identification" and does not allow you to confirm the security exception.

[1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=627552

Comment 1 Huzaifa S. Sidhpurwala 2011-06-01 04:38:28 UTC
Reported upstream via:
https://bugzilla.mozilla.org/show_bug.cgi?id=660749

Comment 2 Josh Bressers 2011-08-25 13:54:20 UTC
There's nothing we can do about this until upstream acts. The issue is quite minor, so I'm closing this UPSTREAM. We'll reopen the bug once it gets fixed.


Note You need to log in before you can comment on or make changes to this bug.