CVE-2014-8642
Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider the id-pkix-ocsp-nocheck extension in deciding whether to trust an OCSP responder, which makes it easier for remote attackers to obtain sensitive information by sniffing the network…
Does this matter?
Lower severity and a low EPSS score (1.50%). Track it; it rarely justifies an emergency change on its own.
Description
Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider the id-pkix-ocsp-nocheck extension in deciding whether to trust an OCSP responder, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which there was an incorrect decision to accept a compromised and revoked certificate.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 1.50% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- mozilla/seamonkey · opensuse/opensuse · mozilla/firefox
- Source
- security@mozilla.org
References
- http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00002.html
- http://secunia.com/advisories/62242
- http://secunia.com/advisories/62250
- http://secunia.com/advisories/62253
- http://secunia.com/advisories/62316
- http://secunia.com/advisories/62418
- http://secunia.com/advisories/62446
- http://secunia.com/advisories/62790
- http://www.mozilla.org/security/announce/2014/mfsa2015-08.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/72042
- http://www.securitytracker.com/id/1031533
- https://bugzilla.mozilla.org/show_bug.cgi?id=1079658
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99963
- https://security.gentoo.org/glsa/201504-01
- http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00002.html
- http://secunia.com/advisories/62242
- http://secunia.com/advisories/62250
- http://secunia.com/advisories/62253
- http://secunia.com/advisories/62316
- http://secunia.com/advisories/62418
- http://secunia.com/advisories/62446
- http://secunia.com/advisories/62790
- http://www.mozilla.org/security/announce/2014/mfsa2015-08.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.securityfocus.com/bid/72042
- http://www.securitytracker.com/id/1031533
- https://bugzilla.mozilla.org/show_bug.cgi?id=1079658
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.