Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-1568

Опубликовано: 24 сент. 2014
Источник: redhat
CVSS2: 5.8
EPSS Средний

Описание

Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.

A flaw was found in the way NSS parsed ASN.1 (Abstract Syntax Notation One) input from certain RSA signatures. A remote attacker could use this flaw to forge RSA certificates by providing a specially crafted signature to an application using NSS.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux Extended Update Support 5.6nssAffected
Red Hat Enterprise Linux 4 Extended Lifecycle SupportnssFixedRHSA-2014:137110.10.2014
Red Hat Enterprise Linux 5nssFixedRHSA-2014:130726.09.2014
Red Hat Enterprise Linux 5.6 Long LifenssFixedRHSA-2014:137110.10.2014
Red Hat Enterprise Linux 5.9 Extended Update SupportnssFixedRHSA-2014:137110.10.2014
Red Hat Enterprise Linux 6nssFixedRHSA-2014:130726.09.2014
Red Hat Enterprise Linux 6nss-softoknFixedRHSA-2014:130726.09.2014
Red Hat Enterprise Linux 6nss-utilFixedRHSA-2014:130726.09.2014
Red Hat Enterprise Linux 6.2 Advanced Update SupportnssFixedRHSA-2014:137110.10.2014
Red Hat Enterprise Linux 6.2 Advanced Update Supportnss-softoknFixedRHSA-2014:137110.10.2014

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=1145429nss: RSA PKCS#1 signature verification forgery flaw (MFSA 2014-73)

EPSS

Процентиль: 97%
0.41418
Средний

5.8 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.

nvd
почти 11 лет назад

Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.

debian
почти 11 лет назад

Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before ...

github
около 3 лет назад

Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.

oracle-oval
почти 11 лет назад

ELSA-2014-1307: nss security update (IMPORTANT)

EPSS

Процентиль: 97%
0.41418
Средний

5.8 Medium

CVSS2