Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote attackers to use certain redirect sequences to spoof the security lock icon that makes a web page appear to be encrypted.
| Software | From | Fixed in |
|---|---|---|
| mozilla / thunderbird | - | 0.7.x |
| mozilla / firefox | - | 0.9.x |
| mozilla / mozilla | - | 1.7.x |