CVE-2014-1492

Description

The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain names U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

Risk Information

Base Score
9.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
1.19

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (129.0)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (129.0.1)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (129.0.2)Mac
Mozilla Open Source web browser (USN-2185-1) firefox_43.0+build1-0ubuntu0.14.04.1_i386.debLinux
Mozilla Open Source web browser (USN-2185-1) firefox_43.0+build1-0ubuntu0.14.04.1_amd64.debLinux
Improper Input Validation Vulnerability (CVE-2014-1492)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234