CVE-2014-1492
Last modified
CVE-2014-1492 is a vulnerability of currently unknown severity. The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.. EPSS estimates a 1.77% chance of exploitation in the next 30 days.
Description
The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Network Security Services | <= 3.15.5 |
| Mozilla | Network Security Services | 3.2 |
| Mozilla | Network Security Services | 3.2.1 |
| Mozilla | Network Security Services | 3.3 |
| Mozilla | Network Security Services | 3.3.1 |
| Mozilla | Network Security Services | 3.3.2 |
| Mozilla | Network Security Services | 3.4 |
| Mozilla | Network Security Services | 3.4.1 |
| Mozilla | Network Security Services | 3.4.2 |
| Mozilla | Network Security Services | 3.5 |
| Mozilla | Network Security Services | 3.6 |
| Mozilla | Network Security Services | 3.6.1 |
| Mozilla | Network Security Services | 3.7 |
| Mozilla | Network Security Services | 3.7.1 |
| Mozilla | Network Security Services | 3.7.2 |
| Mozilla | Network Security Services | 3.7.3 |
| Mozilla | Network Security Services | 3.7.5 |
| Mozilla | Network Security Services | 3.7.7 |
| Mozilla | Network Security Services | 3.8 |
| Mozilla | Network Security Services | 3.9 |
| Mozilla | Network Security Services | 3.11.2 |
| Mozilla | Network Security Services | 3.11.3 |
| Mozilla | Network Security Services | 3.11.4 |
| Mozilla | Network Security Services | 3.11.5 |
| Mozilla | Network Security Services | 3.12 |
| Mozilla | Network Security Services | 3.12.1 |
| Mozilla | Network Security Services | 3.12.2 |
| Mozilla | Network Security Services | 3.12.3 |
| Mozilla | Network Security Services | 3.12.3.1 |
| Mozilla | Network Security Services | 3.12.3.2 |
| Mozilla | Network Security Services | 3.12.4 |
| Mozilla | Network Security Services | 3.12.5 |
| Mozilla | Network Security Services | 3.12.6 |
| Mozilla | Network Security Services | 3.12.7 |
| Mozilla | Network Security Services | 3.12.8 |
| Mozilla | Network Security Services | 3.12.9 |
| Mozilla | Network Security Services | 3.12.10 |
| Mozilla | Network Security Services | 3.12.11 |
| Mozilla | Network Security Services | 3.14 |
| Mozilla | Network Security Services | 3.14.1 |
| Mozilla | Network Security Services | 3.14.2 |
| Mozilla | Network Security Services | 3.14.3 |
| Mozilla | Network Security Services | 3.14.4 |
| Mozilla | Network Security Services | 3.14.5 |
| Mozilla | Network Security Services | 3.15 |
| Mozilla | Network Security Services | 3.15.1 |
| Mozilla | Network Security Services | 3.15.2 |
| Mozilla | Network Security Services | 3.15.3 |
| Mozilla | Network Security Services | 3.15.3.1 |
| Mozilla | Network Security Services | 3.15.4 |
References
- https://hg.mozilla.org/projects/nss/rev/709d4e597979Exploit, Patch
- https://hg.mozilla.org/projects/nss/rev/709d4e597979Exploit, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-1492?
How severe is CVE-2014-1492?
How do I fix CVE-2014-1492?
Are you affected by CVE-2014-1492?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
