CVE-2014-1492
Last modified
CVE-2014-1492 is a vulnerability of currently unknown severity. The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.. EPSS estimates a 1.77% chance of exploitation in the next 30 days.
Description
The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Network Security Services | <= 3.15.5 |
| Mozilla | Network Security Services | 3.2 |
| Mozilla | Network Security Services | 3.2.1 |
| Mozilla | Network Security Services | 3.3 |
| Mozilla | Network Security Services | 3.3.1 |
| Mozilla | Network Security Services | 3.3.2 |
| Mozilla | Network Security Services | 3.4 |
| Mozilla | Network Security Services | 3.4.1 |
| Mozilla | Network Security Services | 3.4.2 |
| Mozilla | Network Security Services | 3.5 |
| Mozilla | Network Security Services | 3.6 |
| Mozilla | Network Security Services | 3.6.1 |
| Mozilla | Network Security Services | 3.7 |
| Mozilla | Network Security Services | 3.7.1 |
| Mozilla | Network Security Services | 3.7.2 |
| Mozilla | Network Security Services | 3.7.3 |
| Mozilla | Network Security Services | 3.7.5 |
| Mozilla | Network Security Services | 3.7.7 |
| Mozilla | Network Security Services | 3.8 |
| Mozilla | Network Security Services | 3.9 |
| Mozilla | Network Security Services | 3.11.2 |
| Mozilla | Network Security Services | 3.11.3 |
| Mozilla | Network Security Services | 3.11.4 |
| Mozilla | Network Security Services | 3.11.5 |
| Mozilla | Network Security Services | 3.12 |
| Mozilla | Network Security Services | 3.12.1 |
| Mozilla | Network Security Services | 3.12.2 |
| Mozilla | Network Security Services | 3.12.3 |
| Mozilla | Network Security Services | 3.12.3.1 |
| Mozilla | Network Security Services | 3.12.3.2 |
| Mozilla | Network Security Services | 3.12.4 |
| Mozilla | Network Security Services | 3.12.5 |
| Mozilla | Network Security Services | 3.12.6 |
| Mozilla | Network Security Services | 3.12.7 |
| Mozilla | Network Security Services | 3.12.8 |
| Mozilla | Network Security Services | 3.12.9 |
| Mozilla | Network Security Services | 3.12.10 |
| Mozilla | Network Security Services | 3.12.11 |
| Mozilla | Network Security Services | 3.14 |
| Mozilla | Network Security Services | 3.14.1 |
| Mozilla | Network Security Services | 3.14.2 |
| Mozilla | Network Security Services | 3.14.3 |
| Mozilla | Network Security Services | 3.14.4 |
| Mozilla | Network Security Services | 3.14.5 |
| Mozilla | Network Security Services | 3.15 |
| Mozilla | Network Security Services | 3.15.1 |
| Mozilla | Network Security Services | 3.15.2 |
| Mozilla | Network Security Services | 3.15.3 |
| Mozilla | Network Security Services | 3.15.3.1 |
| Mozilla | Network Security Services | 3.15.4 |
References
- https://hg.mozilla.org/projects/nss/rev/709d4e597979Exploit, Patch
- https://hg.mozilla.org/projects/nss/rev/709d4e597979Exploit, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-1492?
How severe is CVE-2014-1492?
How do I fix CVE-2014-1492?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-1486Use-after-free vulnerability in the imgRequestProxy function…9.8
- CVE-2014-1487The Web workers implementation in Mozilla Firefox before 27.…7.5
- CVE-2014-1488The Web workers implementation in Mozilla Firefox before 27.…
- CVE-2014-1489Mozilla Firefox before 27.0 does not properly restrict acces…
- CVE-2014-1490Race condition in libssl in Mozilla Network Security Service…
- CVE-2014-1491Mozilla Network Security Services (NSS) before 3.15.4, as us…
- CVE-2014-1493Multiple unspecified vulnerabilities in the browser engine i…9.8
- CVE-2014-1494Multiple unspecified vulnerabilities in the browser engine i…
- CVE-2014-1496Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, T…5.5
- CVE-2014-1497The mozilla::WaveReader::DecodeAudioData function in Mozilla…8.8
- CVE-2014-1498The crypto.generateCRMFRequest method in Mozilla Firefox bef…
- CVE-2014-1499Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow …
Are you affected by CVE-2014-1492?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
