EN

Tracker / CVE-2014-1568

CVE-2014-1568

Alta 7.5

Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.

Prodotti e versioni affette

google chrome
google chrome · … → 37.0.2062.103
google chrome · … → 37.0.2062.120
mozilla firefox
mozilla firefox · … → 32.0
mozilla firefox_esr
mozilla network_security_services
mozilla network_security_services · … → 3.16.2.0
mozilla seamonkey
mozilla seamonkey · … → 2.29
mozilla thunderbird
mozilla thunderbird · … → 24.8.0

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti