Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-1582

Опубликовано: 15 окт. 2014
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3

Описание

The Public Key Pinning (PKP) implementation in Mozilla Firefox before 33.0 does not properly consider the connection-coalescing behavior of SPDY and HTTP/2 in the case of a shared IP address, which allows man-in-the-middle attackers to bypass an intended pinning configuration and spoof a web site by providing a valid certificate from an arbitrary recognized Certification Authority.

РелизСтатусПримечание
devel

released

33.0+build2-0ubuntu0.14.10.1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [33.0+build2-0ubuntu0.14.04.1]]
lucid

ignored

end of life
precise

released

33.0+build2-0ubuntu0.12.04.1
trusty

released

33.0+build2-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [33.0+build2-0ubuntu0.14.04.1]
upstream

released

33.0

Показывать по

EPSS

Процентиль: 65%
0.01186
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
почти 12 лет назад

The Public Key Pinning (PKP) implementation in Mozilla Firefox before 33.0 does not properly consider the connection-coalescing behavior of SPDY and HTTP/2 in the case of a shared IP address, which allows man-in-the-middle attackers to bypass an intended pinning configuration and spoof a web site by providing a valid certificate from an arbitrary recognized Certification Authority.

nvd
почти 12 лет назад

The Public Key Pinning (PKP) implementation in Mozilla Firefox before 33.0 does not properly consider the connection-coalescing behavior of SPDY and HTTP/2 in the case of a shared IP address, which allows man-in-the-middle attackers to bypass an intended pinning configuration and spoof a web site by providing a valid certificate from an arbitrary recognized Certification Authority.

debian
почти 12 лет назад

The Public Key Pinning (PKP) implementation in Mozilla Firefox before ...

github
около 4 лет назад

The Public Key Pinning (PKP) implementation in Mozilla Firefox before 33.0 does not properly consider the connection-coalescing behavior of SPDY and HTTP/2 in the case of a shared IP address, which allows man-in-the-middle attackers to bypass an intended pinning configuration and spoof a web site by providing a valid certificate from an arbitrary recognized Certification Authority.

EPSS

Процентиль: 65%
0.01186
Низкий

4.3 Medium

CVSS2

Уязвимость CVE-2014-1582