CVE-2014-8639
published 2015-01-14CVE-2014-8639: Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers…
PriorityP432medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.90%
77.6th percentile
Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Required) status code, which allows remote HTTP proxy servers to conduct session fixation attacks by providing a cookie name that corresponds to the session cookie of the origin server.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 34.0.5 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 35.0.1+build1-0ubuntu0.14.04.1 | 35.0.1+build1-0ubuntu0.14.04.1 |
| mozilla | firefox | >= 0 < 35.0+build3-0ubuntu0.14.04.2 | 35.0+build3-0ubuntu0.14.04.2 |
| mozilla | firefox_esr | — | — |
| mozilla | seamonkey | <= 2.31 | — |
| mozilla | thunderbird | <= 31.3.0 | — |
| mozilla | thunderbird | >= 0 < 1:31.4.0+build1-0ubuntu0.14.04.1 | 1:31.4.0+build1-0ubuntu0.14.04.1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cfgr-xpqw-rcxf: Mozilla Firefox before 35
ghsa_unreviewed·2022-05-17
CVE-2014-8639 [MEDIUM] GHSA-cfgr-xpqw-rcxf: Mozilla Firefox before 35
Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Required) status code, which allows remote HTTP proxy servers to conduct session fixation attacks by providing a cookie name that corresponds to the session cookie of the origin server.
OSV
firefox regression
osv·2015-01-27·CVSS 7.5
[HIGH] firefox regression
firefox regression
USN-2458-1 fixed vulnerabilities in Firefox. This update introduced a
regression which could make websites that use CSP fail to load under some
circumstances. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Christian Holler, Patrick McManus, Christoph Diehl, Gary Kwong, Jesse
Ruderman, Byron Campen, Terrence Cole, and Nils Ohlmeier discovered
multiple memory safety issues in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
these to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2014-8634, CVE-2014-8635)
Bobby Holley discovered that some DOM objects with certain properties
can
OSV
thunderbird vulnerabilities
osv·2015-01-19·CVSS 7.5
CVE-2014-8634 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
Christian Holler and Patrick McManus discovered multiple memory safety
issues in Thunderbird. If a user were tricked in to opening a specially
crafted message with scripting enabled, an attacker could potentially
exploit these to cause a denial of service via application crash, or
execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2014-8634)
Muneaki Nishimura discovered that requests from navigator.sendBeacon()
lack an origin header. If a user were tricked in to opening a specially
crafted message with scripting enabled, an attacker could potentially
exploit this to conduct cross-site request forgery (XSRF) attacks.
(CVE-2014-8638)
Xiaofeng Zheng discovered that a web proxy returning a 407 response
could inject cookies in to the
OSV
ubufox update
osv·2015-01-14·CVSS 7.5
[HIGH] ubufox update
ubufox update
USN-2458-1 fixed vulnerabilities in Firefox. This update provides the
corresponding version of Ubufox.
Original advisory details:
Christian Holler, Patrick McManus, Christoph Diehl, Gary Kwong, Jesse
Ruderman, Byron Campen, Terrence Cole, and Nils Ohlmeier discovered
multiple memory safety issues in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
these to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2014-8634, CVE-2014-8635)
Bobby Holley discovered that some DOM objects with certain properties
can bypass XrayWrappers in some circumstances. If a user were tricked in
to opening a specially crafted website, an attacker could po
OSV
firefox vulnerabilities
osv·2015-01-14·CVSS 7.5
CVE-2014-8634 [HIGH] firefox vulnerabilities
firefox vulnerabilities
Christian Holler, Patrick McManus, Christoph Diehl, Gary Kwong, Jesse
Ruderman, Byron Campen, Terrence Cole, and Nils Ohlmeier discovered
multiple memory safety issues in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
these to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2014-8634, CVE-2014-8635)
Bobby Holley discovered that some DOM objects with certain properties
can bypass XrayWrappers in some circumstances. If a user were tricked in
to opening a specially crafted website, an attacker could potentially
exploit this to bypass security restrictions. (CVE-2014-8636)
Michal Zalewski discovered a use of uninitialized
OSV
CVE-2014-8639: Mozilla Firefox before 35
osv·2015-01-14·CVSS 6.8
CVE-2014-8639 [MEDIUM] CVE-2014-8639: Mozilla Firefox before 35
Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Required) status code, which allows remote HTTP proxy servers to conduct session fixation attacks by providing a cookie name that corresponds to the session cookie of the origin server.
Ubuntu
Firefox regression
vendor_ubuntu·2015-01-27·CVSS 7.5
[HIGH] Firefox regression
Title: Firefox regression
Summary: USN-2458-1 introduced a regression in Firefox
USN-2458-1 fixed vulnerabilities in Firefox. This update introduced a
regression which could make websites that use CSP fail to load under some
circumstances. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Christian Holler, Patrick McManus, Christoph Diehl, Gary Kwong, Jesse
Ruderman, Byron Campen, Terrence Cole, and Nils Ohlmeier discovered
multiple memory safety issues in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
these to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2014-8634, CVE-2014-8635)
Bobby Holle
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2015-01-19·CVSS 7.5
CVE-2014-8634 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Christian Holler and Patrick McManus discovered multiple memory safety
issues in Thunderbird. If a user were tricked in to opening a specially
crafted message with scripting enabled, an attacker could potentially
exploit these to cause a denial of service via application crash, or
execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2014-8634)
Muneaki Nishimura discovered that requests from navigator.sendBeacon()
lack an origin header. If a user were tricked in to opening a specially
crafted message with scripting enabled, an attacker could potentially
exploit this to conduct cross-site request forgery (XSRF) attacks.
(CVE-2014-8638)
Xiaofeng Zheng discovered that
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2015-01-14·CVSS 7.5
CVE-2014-8634 [HIGH] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Christian Holler, Patrick McManus, Christoph Diehl, Gary Kwong, Jesse
Ruderman, Byron Campen, Terrence Cole, and Nils Ohlmeier discovered
multiple memory safety issues in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
these to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2014-8634, CVE-2014-8635)
Bobby Holley discovered that some DOM objects with certain properties
can bypass XrayWrappers in some circumstances. If a user were tricked in
to opening a specially crafted website, an attacker could potentially
Ubuntu
Ubufox update
vendor_ubuntu·2015-01-14·CVSS 7.5
[HIGH] Ubufox update
Title: Ubufox update
Summary: This update provides compatible packages for Firefox 35.
USN-2458-1 fixed vulnerabilities in Firefox. This update provides the
corresponding version of Ubufox.
Original advisory details:
Christian Holler, Patrick McManus, Christoph Diehl, Gary Kwong, Jesse
Ruderman, Byron Campen, Terrence Cole, and Nils Ohlmeier discovered
multiple memory safety issues in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
these to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2014-8634, CVE-2014-8635)
Bobby Holley discovered that some DOM objects with certain properties
can bypass XrayWrappers in some circumstances. If a user we
Red Hat
Mozilla: Cookie injection through Proxy Authenticate responses (MFSA 2015-04)
vendor_redhat·2015-01-13·CVSS 6.8
CVE-2014-8639 [MEDIUM] CWE-88 Mozilla: Cookie injection through Proxy Authenticate responses (MFSA 2015-04)
Mozilla: Cookie injection through Proxy Authenticate responses (MFSA 2015-04)
Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Required) status code, which allows remote HTTP proxy servers to conduct session fixation attacks by providing a cookie name that corresponds to the session cookie of the origin server.
No detection rules found.
No public exploits indexed.
http://linux.oracle.com/errata/ELSA-2015-0046.htmlhttp://linux.oracle.com/errata/ELSA-2015-0047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-01/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-01/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-01/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-01/msg00036.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.htmlhttp://lists.opensuse.org/opensuse-updates/2015-01/msg00071.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0046.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0047.htmlhttp://secunia.com/advisories/62237http://secunia.com/advisories/62242http://secunia.com/advisories/62250http://secunia.com/advisories/62253http://secunia.com/advisories/62259http://secunia.com/advisories/62273http://secunia.com/advisories/62274http://secunia.com/advisories/62283http://secunia.com/advisories/62293http://secunia.com/advisories/62304http://secunia.com/advisories/62313http://secunia.com/advisories/62315http://secunia.com/advisories/62316http://secunia.com/advisories/62418http://secunia.com/advisories/62446http://secunia.com/advisories/62657http://secunia.com/advisories/62790http://www.debian.org/security/2015/dsa-3127http://www.debian.org/security/2015/dsa-3132http://www.mozilla.org/security/announce/2014/mfsa2015-04.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/72046http://www.securitytracker.com/id/1031533http://www.securitytracker.com/id/1031534http://www.ubuntu.com/usn/USN-2460-1https://bugzilla.mozilla.org/show_bug.cgi?id=1095859https://exchange.xforce.ibmcloud.com/vulnerabilities/99959https://security.gentoo.org/glsa/201504-01http://linux.oracle.com/errata/ELSA-2015-0046.htmlhttp://linux.oracle.com/errata/ELSA-2015-0047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-01/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-01/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-01/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-01/msg00036.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.htmlhttp://lists.opensuse.org/opensuse-updates/2015-01/msg00071.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0046.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0047.htmlhttp://secunia.com/advisories/62237http://secunia.com/advisories/62242http://secunia.com/advisories/62250http://secunia.com/advisories/62253http://secunia.com/advisories/62259http://secunia.com/advisories/62273http://secunia.com/advisories/62274http://secunia.com/advisories/62283http://secunia.com/advisories/62293http://secunia.com/advisories/62304http://secunia.com/advisories/62313http://secunia.com/advisories/62315http://secunia.com/advisories/62316http://secunia.com/advisories/62418http://secunia.com/advisories/62446http://secunia.com/advisories/62657http://secunia.com/advisories/62790http://www.debian.org/security/2015/dsa-3127http://www.debian.org/security/2015/dsa-3132http://www.mozilla.org/security/announce/2014/mfsa2015-04.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/72046http://www.securitytracker.com/id/1031533http://www.securitytracker.com/id/1031534http://www.ubuntu.com/usn/USN-2460-1https://bugzilla.mozilla.org/show_bug.cgi?id=1095859https://exchange.xforce.ibmcloud.com/vulnerabilities/99959https://security.gentoo.org/glsa/201504-01
2015-01-14
Published