Уязвимость доверия к OCSP-ответчикам в Mozilla Firefox и SeaMonkey из-за игнорирования id-pkix-ocsp-nocheck расширения
Описание
В версиях Mozilla Firefox до релиза 35.0 и SeaMonkey до релиза 2.32 не учитывается расширение id-pkix-ocsp-nocheck при принятии решения о доверии к OCSP-ответчику. Это упрощает удалённым злоумышленникам возможность получить доступ к конфиденциальной информации, перехватывая сетевой трафик во время сессии, в которой было принято некорректное решение о принятии скомпрометированного и отозванного сертификата.
Затронутые версии ПО
- Mozilla Firefox до релиза 35.0
- SeaMonkey до релиза 2.32
Тип уязвимости
- Перехват данных
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Одно из
EPSS
4.3 Medium
CVSS2
Дефекты
Связанные уязвимости
Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider the id-pkix-ocsp-nocheck extension in deciding whether to trust an OCSP responder, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which there was an incorrect decision to accept a compromised and revoked certificate.
Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider the id-pkix-ocsp-nocheck extension in deciding whether to trust an OCSP responder, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which there was an incorrect decision to accept a compromised and revoked certificate.
Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider ...
Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider the id-pkix-ocsp-nocheck extension in deciding whether to trust an OCSP responder, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which there was an incorrect decision to accept a compromised and revoked certificate.
EPSS
4.3 Medium
CVSS2