CVE-2014-8642

Severity
4.3MEDIUM
EPSS
0.7%
top 28.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 14
Latest updateMay 14

Description

Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider the id-pkix-ocsp-nocheck extension in deciding whether to trust an OCSP responder, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which there was an incorrect decision to accept a compromised and revoked certificate.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages4 packages

NVDmozilla/firefox34.0.5
Ubuntufirefox< 35.0+build3-0ubuntu0.14.04.2
NVDopensuse/opensuse13.1, 13.2+1

🔴Vulnerability Details

3
GHSA
GHSA-cw54-px9j-p8mf: Mozilla Firefox before 352022-05-14
CVEList
CVE-2014-8642: Mozilla Firefox before 352015-01-14
OSV
CVE-2014-8642: Mozilla Firefox before 352015-01-14

📋Vendor Advisories

2
Red Hat
Mozilla: Delegated OCSP responder certificates failure with id-pkix-ocsp-nocheck extension (MFSA 2015-08)2015-01-15
Ubuntu
Firefox vulnerabilities2015-01-14

💬Community

1
Bugzilla
CVE-2014-8642 Mozilla: Delegated OCSP responder certificates failure with id-pkix-ocsp-nocheck extension (MFSA 2015-08)2015-01-12