关键信息 漏洞ID: Mozilla Foundation Security Advisory 2009-27 漏洞名称: SSL tampering via non-200 responses to proxy CONNECT requests 公告日期: June 11, 2009 报告者: Shuo Chen, Ziqing Mao, Yi-Min Wang, Ming Zhang 影响: High 受影响产品: Firefox, SeaMonkey, Thunderbird 修复版本: - Firefox 3.0.10 - SeaMonkey 1.1.17 - Thunderbird 2.0.0.22 描述: Microsoft security researchers reported a vulnerability where a non-200 response to a CONNECT request can be used by an active network attacker to insert malicious code. The issue is high-severity as it requires the victim to have a proxy configured. Thunderbird mail messages are not vulnerable unless used in a browser-like manner with JavaScript enabled. 参考链接: - Bugzilla - CVE-2009-1836