SSL certificate of previous website used in new tab

RESOLVED INVALID

Status

()

Firefox
Untriaged
RESOLVED INVALID
2 months ago
2 months ago

People

(Reporter: julien, Unassigned)

Tracking

52 Branch
Points:
---

Firefox Tracking Flags

(Not tracked)

Details

Attachments

(1 attachment)

(Reporter)

Description

2 months ago
Created attachment 8906336 [details]
Screenshot_2017-09-10_02-03-24.png

User Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0
Build ID: 20170809204109

Steps to reproduce:

I was on bfmtv (which does not seem to use ssl), tabbed back to reddit, selected some text and right clicked "search google for ..."




Actual results:

google.com opened in new, but was someone trying to use bfmtv's certificates:

www.google.com uses an invalid security certificate. The certificate is only valid for the following names: rmcsport.bfmtv.com, static.bfmtv.com, rmc.bfmtv.com, bfmtv.com, img.bfmtv.com, api.nextradiotv.com, www.bfmtv.com Error code: SSL_ERROR_BAD_CERT_DOMAIN

https://www.google.com/ncr

Unable to communicate securely with peer: requested domain name does not match the server’s certificate.

HTTP Strict Transport Security: true
HTTP Public Key Pinning: true

Certificate chain:

-----BEGIN CERTIFICATE-----
MIIEuzCCBGGgAwIBAgIQMHt0inAqiH3TxO1MsQSqrDAKBggqhkjOPQQDAjCBgDEL
MAkGA1UEBhMCVVMxHTAbBgNVBAoTFFN5bWFudGVjIENvcnBvcmF0aW9uMR8wHQYD
VQQLExZTeW1hbnRlYyBUcnVzdCBOZXR3b3JrMTEwLwYDVQQDEyhTeW1hbnRlYyBD
bGFzcyAzIEVDQyAyNTYgYml0IFNTTCBDQSAtIEcyMB4XDTE3MDUwNDAwMDAwMFoX
DTE4MDUwNDIzNTk1OVowbDELMAkGA1UEBhMCRlIxDjAMBgNVBAgMBVBhcmlzMQ4w
DAYDVQQHDAVQYXJpczEYMBYGA1UECgwPTkVYVElOVEVSQUNUSVZFMQswCQYDVQQL
DAJJVDEWMBQGA1UEAwwNd3d3LmJmbXR2LmNvbTBZMBMGByqGSM49AgEGCCqGSM49
AwEHA0IABOgl3JZfmN6tcABkvWrdqqj1AD9S715lBEnOvPqUOkb1NigGvhpxxt5j
/gnzEFy3M9dt8k/eehBIBlAqmVntrumjggLOMIICyjB8BgNVHREEdTBzghJybWNz
cG9ydC5iZm10di5jb22CEHN0YXRpYy5iZm10di5jb22CDXJtYy5iZm10di5jb22C
CWJmbXR2LmNvbYINaW1nLmJmbXR2LmNvbYITYXBpLm5leHRyYWRpb3R2LmNvbYIN
d3d3LmJmbXR2LmNvbTAJBgNVHRMEAjAAMA4GA1UdDwEB/wQEAwIHgDBhBgNVHSAE
WjBYMFYGBmeBDAECAjBMMCMGCCsGAQUFBwIBFhdodHRwczovL2Quc3ltY2IuY29t
L2NwczAlBggrBgEFBQcCAjAZDBdodHRwczovL2Quc3ltY2IuY29tL3JwYTArBgNV
HR8EJDAiMCCgHqAchhpodHRwOi8vcmMuc3ltY2IuY29tL3JjLmNybDAdBgNVHSUE
FjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwHwYDVR0jBBgwFoAUJfCK4Ut62QGVCu3G
U/GMeB/Z8/gwVwYIKwYBBQUHAQEESzBJMB8GCCsGAQUFBzABhhNodHRwOi8vcmMu
c3ltY2QuY29tMCYGCCsGAQUFBzAChhpodHRwOi8vcmMuc3ltY2IuY29tL3JjLmNy
dDCCAQQGCisGAQQB1nkCBAIEgfUEgfIA8AB1AN3rHSt6DU+mIIuBrYFocH4ujp0B
1VyIjT0RxM227L7MAAABW9QHXZ4AAAQDAEYwRAIge0bkeYRJMNxNsJXhaMwKRsYL
tj3FHNNE4jOs6V+sjdoCIEnSH58NJmnwQYfSntuhU9T827lAAmOo3iBGc7cKuEW6
AHcApLkJkLQYWBSHuxOizGdwCjw1mAT5G9+443fNDsgN3BAAAAFb1Add0AAABAMA
SDBGAiEA4WwjZcNH9X03V1Erd9oZoAYhufM77lhhdzI1pctyOO8CIQDdnnGkl7EP
7cEcdFGNeNWUJg3oUMkoNiyaJ8GTtF7QjDAKBggqhkjOPQQDAgNIADBFAiEAkNuo
j/Injih7m6fkuKUIC6MTPaV0a88coiprF7ISh/ICIHFGqAFwOwLL0yZaRK0yu8vV
1c60D+A6jqq7Fmkz6TA2
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIEajCCA1KgAwIBAgIQP5KHvp0dpKN6nfYoLndaxDANBgkqhkiG9w0BAQsFADCB
yjELMAkGA1UEBhMCVVMxFzAVBgNVBAoTDlZlcmlTaWduLCBJbmMuMR8wHQYDVQQL
ExZWZXJpU2lnbiBUcnVzdCBOZXR3b3JrMTowOAYDVQQLEzEoYykgMjAwNiBWZXJp
U2lnbiwgSW5jLiAtIEZvciBhdXRob3JpemVkIHVzZSBvbmx5MUUwQwYDVQQDEzxW
ZXJpU2lnbiBDbGFzcyAzIFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0
aG9yaXR5IC0gRzUwHhcNMTUwNTEyMDAwMDAwWhcNMjUwNTExMjM1OTU5WjCBgDEL
MAkGA1UEBhMCVVMxHTAbBgNVBAoTFFN5bWFudGVjIENvcnBvcmF0aW9uMR8wHQYD
VQQLExZTeW1hbnRlYyBUcnVzdCBOZXR3b3JrMTEwLwYDVQQDEyhTeW1hbnRlYyBD
bGFzcyAzIEVDQyAyNTYgYml0IFNTTCBDQSAtIEcyMFkwEwYHKoZIzj0CAQYIKoZI
zj0DAQcDQgAEDxukkdfnrOfRTk63ZFvhj39uBNOrONtEt0Bcbb2WljffeYmGZ/ex
Hwie/WM7RoyfvVPoFdyXPiuBRq2Gfw4BOaOCAV0wggFZMC4GCCsGAQUFBwEBBCIw
IDAeBggrBgEFBQcwAYYSaHR0cDovL3Muc3ltY2QuY29tMBIGA1UdEwEB/wQIMAYB
Af8CAQAwZQYDVR0gBF4wXDBaBgpghkgBhvhFAQc2MEwwIwYIKwYBBQUHAgEWF2h0
dHBzOi8vZC5zeW1jYi5jb20vY3BzMCUGCCsGAQUFBwICMBkaF2h0dHBzOi8vZC5z
eW1jYi5jb20vcnBhMC8GA1UdHwQoMCYwJKAioCCGHmh0dHA6Ly9zLnN5bWNiLmNv
bS9wY2EzLWc1LmNybDAOBgNVHQ8BAf8EBAMCAQYwKwYDVR0RBCQwIqQgMB4xHDAa
BgNVBAMTE1NZTUMtRUNDLUNBLXAyNTYtMjIwHQYDVR0OBBYEFCXwiuFLetkBlQrt
xlPxjHgf2fP4MB8GA1UdIwQYMBaAFH/TZafC3ey78DAJ80M5+gKvMzEzMA0GCSqG
SIb3DQEBCwUAA4IBAQAMMGUXBaWTdaLxsTGtcB/naqjIQrLvoV9NG+7MoHpGd/69
dZ/h2zOy7sGFUHoG/0HGRA9rxT/5w5GkEVIVkxtWyIWWq6rs4CTZt8Bej/KHYRbo
jtEDUkCTZSTLiCvguPyvinXgxy+LHT+PmdtEfXsvcdbeBSWUYpOsDYvD2hNtz9dw
Od5nBosMApmdxt+z7LQyZu8wMnfI1U6IMO+RWowxZ8uy0oswdFYd32l9xe+aAE/k
y9alLu/M9pvxiUKufqHJRgDBKA6uDjHLMPX+/nxXaNCPX3SI4KVZ1stHQ/U5oNlM
dHN9umAvlU313g0IgJrjsQ2nIdf9dsdP+6lrmP7s
-----END CERTIFICATE-----



Expected results:

Please note that I tried rm -fr ~/.cache, clearing firefox cache, restart firefox. issue persists and while not blocking (I can still use google.fr), could be very blocking if it has happened on other sites.

Also, after all my tries of clearing things, currently not resolved.
(Reporter)

Comment 1

2 months ago
Notes:
Happened on a Debian buster, Firefox ESR 52.3.0 (64-bit), plugins are uBlock Origin, privacybadger, Saved Password Editor and Video DownloadHelper.

I managed somehow to restore normal behavior after several attempts at restarting firefox (safe and normal mode) interleaved with deletions of ~/.cache and cache+history, cookies within firefox.
(Reporter)

Comment 2

2 months ago
(In reply to julien from comment #1)
> Notes:
> Happened on a Debian buster, Firefox ESR 52.3.0 (64-bit), plugins are uBlock
> Origin, privacybadger, Saved Password Editor and Video DownloadHelper.
> 
> I managed somehow to restore normal behavior after several attempts at
> restarting firefox (safe and normal mode) interleaved with deletions of
> ~/.cache and cache+history, cookies within firefox.

Cross that out... it's happening again.
Closing as it works normally with Safe Mode.
Status: UNCONFIRMED → RESOLVED
Last Resolved: 2 months ago
Resolution: --- → INVALID
You need to log in before you can comment on or make changes to this bug.