UBUNTU-CVE-2014-1492
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-1492
UBUNTU-CVE-2014-1492
Summary:
Details: The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
References: https://ubuntu.com/security/CVE-2014-1492, https://developer.mozilla.org/en-US/docs/NSS/NSS_3.16_release_notes, https://ubuntu.com/security/notices/USN-2159-1, http://www.mozilla.org/security/announce/2014/mfsa2014-45.html, https://ubuntu.com/security/notices/USN-2185-1, https://www.cve.org/CVERecord?id=CVE-2014-1492
Affected packages
Package
Name: firefox
Purl: pkg:deb/ubuntu/[email protected]+build1-0ubuntu0.14.04.2?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
