Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-1568

Опубликовано: 25 сент. 2014
Источник: ubuntu
Приоритет: high
EPSS Средний
CVSS2: 7.5

Описание

Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.

РелизСтатусПримечание
devel

released

32.0.3+build1-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [32.0.3+build1-0ubuntu0.14.04.1]]
lucid

ignored

end of life
precise

released

32.0.3+build1-0ubuntu0.12.04.1
trusty

released

32.0.3+build1-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [32.0.3+build1-0ubuntu0.14.04.1]
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

released

2:3.17.1-0ubuntu1
esm-infra-legacy/trusty

released

2:3.17.1-0ubuntu0.14.04.1
lucid

released

3.17.1-0ubuntu0.10.04.1
precise

released

3.17.1-0ubuntu0.12.04.1
trusty

released

2:3.17.1-0ubuntu0.14.04.1
trusty/esm

released

2:3.17.1-0ubuntu0.14.04.1
upstream

released

3.17.1

Показывать по

РелизСтатусПримечание
devel

released

1:31.1.2+build1-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1:31.1.2+build1-0ubuntu0.14.04.1]]
lucid

ignored

end of life
precise

released

1:31.1.2+build1-0ubuntu0.12.04.1
trusty

released

1:31.1.2+build1-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [1:31.1.2+build1-0ubuntu0.14.04.1]
upstream

needs-triage

Показывать по

EPSS

Процентиль: 97%
0.36836
Средний

7.5 High

CVSS2

Связанные уязвимости

redhat
около 11 лет назад

Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.

nvd
около 11 лет назад

Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.

debian
около 11 лет назад

Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before ...

github
больше 3 лет назад

Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.

oracle-oval
около 11 лет назад

ELSA-2014-1307: nss security update (IMPORTANT)

EPSS

Процентиль: 97%
0.36836
Средний

7.5 High

CVSS2