Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 8 min 101 bronnen 1 kritiek 35 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2014-1498

MEDIUM · 5.0 CVSS Gepubliceerd: CWE-347

Beschrijving

The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not properly validate a certain key type, which allows remote attackers to cause a denial of service (application crash) via vectors that trigger generation of a key that supports the Elliptic Curve ec-dual-use algorithm.

Vendors

Suse Oracle Opensuse Opensuse Project Mozilla

Affected products

Linux Enterprise Desktop Linux Enterprise Server Linux Enterprise Software Development Kit Solaris Opensuse Seamonkey Firefox

References