FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Mozilla -- redirection to insecure site

Affected packages
firefox < 134.0,2
librewolf < 134.0
firefox-esr < 128.6.0
thunderbird < 134.0

Details

VuXML ID f02e3c59-116c-11f0-8b2c-b42e991fc52e
Discovery 2025-01-07
Entry 2025-04-04

security@mozilla.org reports:

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site.

References

CVE Name CVE-2025-0239
URL https://nvd.nist.gov/vuln/detail/CVE-2025-0239