CVE Database
/

CVE-2014-1568

Back to search

CVE-2014-1568

Published: Sep 25, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.

VendorProductVersions

n/a

n/a

affected
n/a

References

VU#772676
third-party-advisory
x_refsource_CERT-VN
RHSA-2014:1307
vendor-advisory
x_refsource_REDHAT
70116
vdb-entry
x_refsource_BID
USN-2360-1
vendor-advisory
x_refsource_UBUNTU
61575
third-party-advisory
x_refsource_SECUNIA
SUSE-SU-2014:1220
vendor-advisory
x_refsource_SUSE
GLSA-201504-01
vendor-advisory
x_refsource_GENTOO
61574
third-party-advisory
x_refsource_SECUNIA
USN-2361-1
vendor-advisory
x_refsource_UBUNTU
DSA-3033
vendor-advisory
x_refsource_DEBIAN
DSA-3034
vendor-advisory
x_refsource_DEBIAN
RHSA-2014:1371
vendor-advisory
x_refsource_REDHAT
RHSA-2014:1354
vendor-advisory
x_refsource_REDHAT
DSA-3037
vendor-advisory
x_refsource_DEBIAN
openSUSE-SU-2014:1224
vendor-advisory
x_refsource_SUSE
USN-2360-2
vendor-advisory
x_refsource_UBUNTU
61540
third-party-advisory
x_refsource_SECUNIA
61576
third-party-advisory
x_refsource_SECUNIA
openSUSE-SU-2014:1232
vendor-advisory
x_refsource_SUSE
61583
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now