PT-2014-1379 · Mozilla+6 · Seamonkey+10

Published

2014-09-20

·

Updated

2025-12-03

·

CVE-2014-1568

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mozilla Network Security Services (NSS) versions prior to 3.16.2.1 Mozilla Firefox versions prior to 32.0.3 Mozilla Firefox ESR versions prior to 24.8.1 and 31.x prior to 31.1.1 Mozilla Thunderbird versions prior to 24.8.1 and 31.x prior to 31.1.2 Mozilla SeaMonkey version prior to 2.29.1 Google Chrome versions prior to 37.0.2062.124 on Windows and OS X Google Chrome OS version prior to 37.0.2062.120
Description The issue exists due to incorrect parsing of ASN.1 values in X.509 certificates, which allows remote attackers to spoof RSA signatures via a crafted certificate, also known as a "signature malleability" issue. This enables attackers to substitute RSA signatures using specially formed certificates.
Recommendations For Mozilla Network Security Services (NSS) versions prior to 3.16.2.1, update to version 3.16.2.1 or later. For Mozilla Firefox versions prior to 32.0.3, update to version 32.0.3 or later. For Mozilla Firefox ESR versions prior to 24.8.1 and 31.x prior to 31.1.1, update to version 24.8.1 or 31.1.1 or later. For Mozilla Thunderbird versions prior to 24.8.1 and 31.x prior to 31.1.2, update to version 24.8.1 or 31.1.2 or later. For Mozilla SeaMonkey version prior to 2.29.1, update to version 2.29.1 or later. For Google Chrome versions prior to 37.0.2062.124 on Windows and OS X, update to version 37.0.2062.124 or later. For Google Chrome OS version prior to 37.0.2062.120, update to version 37.0.2062.120 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2192
ALT-PU-2014-2196
ALT-PU-2014-2197
ALT-PU-2014-2225
ALT-PU-2014-2226
ALT-PU-2015-1464
BDU:2015-00241
BDU:2015-00450
BDU:2015-00466
BDU:2015-00677
BDU:2015-00709
BDU:2015-10003
CESA-2014_1307
CVE-2014-1568
DLA-62-1
DSA-3033-1
DSA-3034-1
DSA-3037-1
MGASA-2014-0391
OPENSUSE-SU-2014_1232-1
OPENSUSE-SU-2024:10451-1
RHSA-2014:1307
RHSA-2014:1354
RHSA-2014:1371
RHSA-2014_1307
SUSE-SU-2014_1220-1
SUSE-SU-2014_1220-2
SUSE-SU-2014_1220-3
SUSE-SU-2014_1220-4
SUSE-SU-2014_1510-1
USN-2360-1
USN-2360-2
USN-2361-1

Affected Products

Alt Linux
Centos
Firefox
Firefox Esr
Google Chrome
Network Security Services
Red Hat
Seamonkey
Suse
Thunderbird
Ubuntu