CVE-2014-1492
published 2014-03-25CVE-2014-1492: The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.77%
75.7th percentile
The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
Affected
56 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nss | < nss 2:3.16-1 (bookworm) | nss 2:3.16-1 (bookworm) |
| mozilla | firefox | >= 0 < 29.0+build1-0ubuntu0.14.04.2 | 29.0+build1-0ubuntu0.14.04.2 |
| mozilla | network_security_services | <= 3.15.5 | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2014-04-29·CVSS 8.8
CVE-2014-1518 [HIGH] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Bobby Holley, Carsten Book, Christoph Diehl, Gary Kwong, Jan de Mooij,
Jesse Ruderman, Nathan Froyd, John Schoenick, Karl Tomlinson, Vladimir
Vukicevic and Christian Holler discovered multiple memory safety issues in
Firefox. If a user were tricked in to opening a specially crafted website,
an attacker could potentially exploit these to cause a denial of service
via application crash, or execute arbitrary code with the privileges of
the user invoking Firefox. (CVE-2014-1518, CVE-2014-1519)
An out of bounds read was discovered in Web Audio. An attacker could
potentially exploit this cause a denial of service via application crash
or execute arbitrary code
Ubuntu
NSS vulnerability
vendor_ubuntu·2014-04-02
CVE-2014-1492 NSS vulnerability
Title: NSS vulnerability
Summary: NSS could be made to expose sensitive information over the network.
It was discovered that NSS incorrectly handled wildcard certificates when
used with internationalized domain names. If a remote attacker were able to
perform a machine-in-the-middle attack, this flaw could be exploited to spoof
SSL servers.
Instructions: After a standard system update you need to restart any applications that
use NSS, such as Evolution and Chromium, to make all the necessary changes.
Red Hat
nss: IDNA hostname matching code does not follow RFC 6125 recommendation (MFSA 2014-45)
vendor_redhat·2014-03-18·CVSS 4.3
CVE-2014-1492 [MEDIUM] CWE-172 nss: IDNA hostname matching code does not follow RFC 6125 recommendation (MFSA 2014-45)
nss: IDNA hostname matching code does not follow RFC 6125 recommendation (MFSA 2014-45)
The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
It was found that the implementation of Internationalizing Domain Names in Applications (IDNA) hostname matching in NSS did not follow the RFC 6125 recommendations. This could lead to certain invalid certificates with international characters to be accepted as valid.
Debian
CVE-2014-1492: nss - The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checkin...
vendor_debian·2014·CVSS 4.3
CVE-2014-1492 [MEDIUM] CVE-2014-1492: nss - The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checkin...
The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
Scope: local
bookworm: resolved (fixed in 2:3.16-1)
bullseye: resolved (fixed in 2:3.16-1)
forky: resolved (fixed in 2:3.16-1)
sid: resolved (fixed in 2:3.16-1)
trixie: resolved (fixed in 2:3.16-1)
VulDB
Mozilla Network Security Services up to 3.14.1 Domain Name Wildcard input validation (Bug 903885 / Nessus ID 75346)
vuldb·2026-05-09·CVSS 4.3
CVE-2014-1492 [MEDIUM] Mozilla Network Security Services up to 3.14.1 Domain Name Wildcard input validation (Bug 903885 / Nessus ID 75346)
A vulnerability classified as problematic has been found in Mozilla Network Security Services up to 3.14.1. Affected by this vulnerability is an unknown functionality of the component Domain Name Handler. The manipulation as part of Wildcard leads to improper input validation.
This vulnerability is listed as CVE-2014-1492. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
VulDB
Mozilla Network Security Services up to 3.14.1 p12creat.c sec_pkcs12_new_asafe input validation (Bug 974693 / Nessus ID 75346)
vuldb·2026-05-09·CVSS 4.3
CVE-2014-1492 [MEDIUM] Mozilla Network Security Services up to 3.14.1 p12creat.c sec_pkcs12_new_asafe input validation (Bug 974693 / Nessus ID 75346)
A vulnerability classified as critical was found in Mozilla Network Security Services up to 3.14.1. Affected by this issue is the function sec_pkcs12_new_asafe of the file p12creat.c. The manipulation results in improper input validation.
This vulnerability is cataloged as CVE-2014-1492. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
GHSA
GHSA-fxvw-6w4h-3mx5: The cert_TestHostName function in lib/certdb/certdb
ghsa_unreviewed·2022-05-14
CVE-2014-1492 [MEDIUM] CWE-20 GHSA-fxvw-6w4h-3mx5: The cert_TestHostName function in lib/certdb/certdb
The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
OSV
firefox vulnerabilities
osv·2014-04-29·CVSS 8.8
[HIGH] firefox vulnerabilities
firefox vulnerabilities
Bobby Holley, Carsten Book, Christoph Diehl, Gary Kwong, Jan de Mooij,
Jesse Ruderman, Nathan Froyd, John Schoenick, Karl Tomlinson, Vladimir
Vukicevic and Christian Holler discovered multiple memory safety issues in
Firefox. If a user were tricked in to opening a specially crafted website,
an attacker could potentially exploit these to cause a denial of service
via application crash, or execute arbitrary code with the privileges of
the user invoking Firefox. (CVE-2014-1518, CVE-2014-1519)
An out of bounds read was discovered in Web Audio. An attacker could
potentially exploit this cause a denial of service via application crash
or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2014-1522)
Abhishek Arya discovered an out of bounds re
OSV
CVE-2014-1492: The cert_TestHostName function in lib/certdb/certdb
osv·2014-03-25·CVSS 4.3
CVE-2014-1492 [MEDIUM] CVE-2014-1492: The cert_TestHostName function in lib/certdb/certdb
The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1855 ruby: OpenSSL extension hostname matching implementation violates RFC 6125
bugzilla·2015-04-08·CVSS 4.3
CVE-2015-1855 [MEDIUM] CVE-2015-1855 ruby: OpenSSL extension hostname matching implementation violates RFC 6125
CVE-2015-1855 ruby: OpenSSL extension hostname matching implementation violates RFC 6125
Ruby OpenSSL hostname matching implementation violates RFC 6125.
- Wildcard matching code allowed multiple wildcards (e.g. *.*.*)
- Wildcards were mishandled for IDNA names (ala CVE-2014-1492)
Upstream patch:
https://github.com/ruby/openssl/commit/e9a7bcb8bf2902f907c148a00bbcf21d3fa79596
Discussion:
Created ruby tracking bugs for this issue:
Affects: fedora-all [bug 1209982]
---
Fixed upstream in Ruby versions: 2.0.0p645, 2.1.6, and 2.2.2
Upstream bug report:
https://bugs.ruby-lang.org/issues/9644
Upstream commit in ruby SVN:
http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=revision&revision=50292
External References:
https://www.ruby-lang.org/en/news/2015/04/13/ruby-openssl-hostname-matchin
Bugzilla
CVE-2014-1492 nss: IDNA hostname matching code does not follow RFC 6125 recommendation (MFSA 2014-45)
bugzilla·2014-03-24·CVSS 4.3
CVE-2014-1492 [MEDIUM] CVE-2014-1492 nss: IDNA hostname matching code does not follow RFC 6125 recommendation (MFSA 2014-45)
CVE-2014-1492 nss: IDNA hostname matching code does not follow RFC 6125 recommendation (MFSA 2014-45)
In a wildcard certificate, the wildcard character should not be embedded within the U-label of an internationalized domain name. This was not properly implemented in NSS, as a result it did not handle IDNA domain prefixes according to RFC 6125, section 6.4.3 "Checking of Wildcard Certificates".
http://tools.ietf.org/html/rfc6125#section-6.4.3
Upstream patch:
https://hg.mozilla.org/projects/nss/rev/15ea62260c21
https://hg.mozilla.org/projects/nss/rev/2ffa40a3ff55
https://hg.mozilla.org/projects/nss/rev/709d4e597979
Upstream bug (not public):
https://bugzilla.mozilla.org/show_bug.cgi?id=903885
This issue was fixed upstream in NSS 3.16:
https://developer.mozilla.org/en-US/docs/NSS/NSS_3.1
Bugzilla
Hostname matching code violates RFC 6125 for IDNA
bugzilla·2013-08-11
[MEDIUM] Hostname matching code violates RFC 6125 for IDNA
Hostname matching code violates RFC 6125 for IDNA
User Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:23.0) Gecko/20100101 Firefox/23.0 (Beta/Release)
Build ID: 20130803192641
Steps to reproduce:
The implementation of cert_TestHostName() at http://hg.mozilla.org/mozilla-central/file/3d20597e0a07/security/nss/lib/certdb/certdb.c#l1384 does not handle IDNA domain prefixes according to RFC 6125, section 6.4.3 "Checking of Wildcard Certificates". http://tools.ietf.org/html/rfc6125#section-6.4.3
Actual results:
A CN or subjectAltName DNS wildcard such as 'x*.example.org' should not match a IDNA A-label like 'xn--www-una.example.org'.
Expected results:
cert_TestHostName() should not use wildcard matching if the first fragment of a hostname is an IDNA A-label. Chromium has such a spec
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132437.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-05/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-05/msg00015.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00010.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00033.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/59866http://secunia.com/advisories/60621http://secunia.com/advisories/60794http://www.debian.org/security/2014/dsa-2994http://www.mozilla.org/security/announce/2014/mfsa2014-45.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/66356http://www.ubuntu.com/usn/USN-2159-1http://www.ubuntu.com/usn/USN-2185-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=903885https://bugzilla.redhat.com/show_bug.cgi?id=1079851https://developer.mozilla.org/en-US/docs/NSS/NSS_3.16_release_noteshttps://hg.mozilla.org/projects/nss/rev/709d4e597979https://security.gentoo.org/glsa/201504-01http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132437.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-05/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-05/msg00015.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00010.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00033.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/59866http://secunia.com/advisories/60621http://secunia.com/advisories/60794http://www.debian.org/security/2014/dsa-2994http://www.mozilla.org/security/announce/2014/mfsa2014-45.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/66356http://www.ubuntu.com/usn/USN-2159-1http://www.ubuntu.com/usn/USN-2185-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=903885https://bugzilla.redhat.com/show_bug.cgi?id=1079851https://developer.mozilla.org/en-US/docs/NSS/NSS_3.16_release_noteshttps://hg.mozilla.org/projects/nss/rev/709d4e597979https://security.gentoo.org/glsa/201504-01
2014-03-25
Published