SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-1568

Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x…

HIGH 7.5EPSS 16.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 16.7%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
16.70% probability · 97th percentile
CISA KEV
Not listed
Weakness
CWE-310
Affected
google/chrome · mozilla/firefox · mozilla/firefox esr · mozilla/network security services · mozilla/seamonkey · mozilla/thunderbird
Source
security@mozilla.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.