This site will have limited functionality while we undergo maintenance to improve your experience. If an article doesn't solve your issue and you want to ask a question, we have our support community waiting to help you at @FirefoxSupport on Twitter and/r/firefox on Reddit.

Search Support

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More

Error: potentially vulnerable to CVE-2009-3555 (facebook). I keep getting kicked out of Facebook and have to re log in

  • 3 பதிலளிப்புகள்
  • 30 இந்த பிரச்னைகள் உள்ளது
  • 1 view
  • Last reply by cor-el

When in Facebook, I keep getting a window that I'm not logged in if I am on the site for about 10 minutes. I checked the error console and it told me that there is a possibility of being vulnerable. I cleared cookies and caches and also changed my password and restarted, but it's not helping. Is there anything I can do to fix this? I also got the vulnerability error for Delicious bookmarks, so I disabled it. I'm on a Mac with the latest upgrade.

URL of affected sites

http://www.facebook.com

When in Facebook, I keep getting a window that I'm not logged in if I am on the site for about 10 minutes. I checked the error console and it told me that there is a possibility of being vulnerable. I cleared cookies and caches and also changed my password and restarted, but it's not helping. Is there anything I can do to fix this? I also got the vulnerability error for Delicious bookmarks, so I disabled it. I'm on a Mac with the latest upgrade. == URL of affected sites == http://www.facebook.com

All Replies (3)

That message is meant for webmasters to make them aware that they need to fix their servers. Firefox 3.6 versions can detect such a misconfiguration and displays a warning in the "Tools > Error Console".

See also https://wiki.mozilla.org/Security:Renegotiation

Thanks to this error code, potentially vulnerable to cve 2009 3555, it blocked a download of upgraded firmware on a SA2RGA04 Philips Gogear Raga, brand new out of the box, but not before it deleted the old version, which rendered it useless. Windows XP don't even recognize it as Nand Flash Mass Storage class Compliant, but only as a USB Human Interface Device.

See this link for information about 'Renegotiation' (CVE-2009-3555):

You can look at the pref security.ssl.renego_unrestricted_hosts on the about:config page and add the sites that you want to allow to the string value.
Separate multiple host names by a comma.