CVE-2014-8642
published 2015-01-14CVE-2014-8642: Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider the id-pkix-ocsp-nocheck extension in deciding whether to trust an OCSP responder, which…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.57%
72.6th percentile
Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider the id-pkix-ocsp-nocheck extension in deciding whether to trust an OCSP responder, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which there was an incorrect decision to accept a compromised and revoked certificate.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 34.0.5 | — |
| mozilla | firefox | >= 0 < 35.0.1+build1-0ubuntu0.14.04.1 | 35.0.1+build1-0ubuntu0.14.04.1 |
| mozilla | firefox | >= 0 < 35.0+build3-0ubuntu0.14.04.2 | 35.0+build3-0ubuntu0.14.04.2 |
| mozilla | seamonkey | <= 2.31 | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cw54-px9j-p8mf: Mozilla Firefox before 35
ghsa_unreviewed·2022-05-14
CVE-2014-8642 [MEDIUM] GHSA-cw54-px9j-p8mf: Mozilla Firefox before 35
Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider the id-pkix-ocsp-nocheck extension in deciding whether to trust an OCSP responder, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which there was an incorrect decision to accept a compromised and revoked certificate.
OSV
firefox regression
osv·2015-01-27·CVSS 7.5
[HIGH] firefox regression
firefox regression
USN-2458-1 fixed vulnerabilities in Firefox. This update introduced a
regression which could make websites that use CSP fail to load under some
circumstances. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Christian Holler, Patrick McManus, Christoph Diehl, Gary Kwong, Jesse
Ruderman, Byron Campen, Terrence Cole, and Nils Ohlmeier discovered
multiple memory safety issues in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
these to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2014-8634, CVE-2014-8635)
Bobby Holley discovered that some DOM objects with certain properties
can
OSV
ubufox update
osv·2015-01-14·CVSS 7.5
[HIGH] ubufox update
ubufox update
USN-2458-1 fixed vulnerabilities in Firefox. This update provides the
corresponding version of Ubufox.
Original advisory details:
Christian Holler, Patrick McManus, Christoph Diehl, Gary Kwong, Jesse
Ruderman, Byron Campen, Terrence Cole, and Nils Ohlmeier discovered
multiple memory safety issues in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
these to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2014-8634, CVE-2014-8635)
Bobby Holley discovered that some DOM objects with certain properties
can bypass XrayWrappers in some circumstances. If a user were tricked in
to opening a specially crafted website, an attacker could po
OSV
CVE-2014-8642: Mozilla Firefox before 35
osv·2015-01-14·CVSS 4.3
CVE-2014-8642 [MEDIUM] CVE-2014-8642: Mozilla Firefox before 35
Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider the id-pkix-ocsp-nocheck extension in deciding whether to trust an OCSP responder, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which there was an incorrect decision to accept a compromised and revoked certificate.
OSV
firefox vulnerabilities
osv·2015-01-14·CVSS 7.5
CVE-2014-8634 [HIGH] firefox vulnerabilities
firefox vulnerabilities
Christian Holler, Patrick McManus, Christoph Diehl, Gary Kwong, Jesse
Ruderman, Byron Campen, Terrence Cole, and Nils Ohlmeier discovered
multiple memory safety issues in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
these to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2014-8634, CVE-2014-8635)
Bobby Holley discovered that some DOM objects with certain properties
can bypass XrayWrappers in some circumstances. If a user were tricked in
to opening a specially crafted website, an attacker could potentially
exploit this to bypass security restrictions. (CVE-2014-8636)
Michal Zalewski discovered a use of uninitialized
Ubuntu
Firefox regression
vendor_ubuntu·2015-01-27·CVSS 7.5
[HIGH] Firefox regression
Title: Firefox regression
Summary: USN-2458-1 introduced a regression in Firefox
USN-2458-1 fixed vulnerabilities in Firefox. This update introduced a
regression which could make websites that use CSP fail to load under some
circumstances. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Christian Holler, Patrick McManus, Christoph Diehl, Gary Kwong, Jesse
Ruderman, Byron Campen, Terrence Cole, and Nils Ohlmeier discovered
multiple memory safety issues in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
these to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2014-8634, CVE-2014-8635)
Bobby Holle
Red Hat
Mozilla: Delegated OCSP responder certificates failure with id-pkix-ocsp-nocheck extension (MFSA 2015-08)
vendor_redhat·2015-01-15·CVSS 4.3
CVE-2014-8642 [MEDIUM] CWE-295 Mozilla: Delegated OCSP responder certificates failure with id-pkix-ocsp-nocheck extension (MFSA 2015-08)
Mozilla: Delegated OCSP responder certificates failure with id-pkix-ocsp-nocheck extension (MFSA 2015-08)
Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider the id-pkix-ocsp-nocheck extension in deciding whether to trust an OCSP responder, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which there was an incorrect decision to accept a compromised and revoked certificate.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: firefox (Red Hat Enterprise Linux 5) - Will not fix
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Will not fix
Package: thu
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2015-01-14·CVSS 7.5
CVE-2014-8634 [HIGH] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Christian Holler, Patrick McManus, Christoph Diehl, Gary Kwong, Jesse
Ruderman, Byron Campen, Terrence Cole, and Nils Ohlmeier discovered
multiple memory safety issues in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
these to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2014-8634, CVE-2014-8635)
Bobby Holley discovered that some DOM objects with certain properties
can bypass XrayWrappers in some circumstances. If a user were tricked in
to opening a specially crafted website, an attacker could potentially
Ubuntu
Ubufox update
vendor_ubuntu·2015-01-14·CVSS 7.5
[HIGH] Ubufox update
Title: Ubufox update
Summary: This update provides compatible packages for Firefox 35.
USN-2458-1 fixed vulnerabilities in Firefox. This update provides the
corresponding version of Ubufox.
Original advisory details:
Christian Holler, Patrick McManus, Christoph Diehl, Gary Kwong, Jesse
Ruderman, Byron Campen, Terrence Cole, and Nils Ohlmeier discovered
multiple memory safety issues in Firefox. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
these to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2014-8634, CVE-2014-8635)
Bobby Holley discovered that some DOM objects with certain properties
can bypass XrayWrappers in some circumstances. If a user we
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00002.htmlhttp://secunia.com/advisories/62242http://secunia.com/advisories/62250http://secunia.com/advisories/62253http://secunia.com/advisories/62316http://secunia.com/advisories/62418http://secunia.com/advisories/62446http://secunia.com/advisories/62790http://www.mozilla.org/security/announce/2014/mfsa2015-08.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/72042http://www.securitytracker.com/id/1031533https://bugzilla.mozilla.org/show_bug.cgi?id=1079658https://exchange.xforce.ibmcloud.com/vulnerabilities/99963https://security.gentoo.org/glsa/201504-01http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-02/msg00002.htmlhttp://secunia.com/advisories/62242http://secunia.com/advisories/62250http://secunia.com/advisories/62253http://secunia.com/advisories/62316http://secunia.com/advisories/62418http://secunia.com/advisories/62446http://secunia.com/advisories/62790http://www.mozilla.org/security/announce/2014/mfsa2015-08.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/72042http://www.securitytracker.com/id/1031533https://bugzilla.mozilla.org/show_bug.cgi?id=1079658https://exchange.xforce.ibmcloud.com/vulnerabilities/99963https://security.gentoo.org/glsa/201504-01
2015-01-14
Published