[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Mozilla Products: Key pinning bypasses - CVE-2014-1584 (Mac OS X)

ID: oval:org.secpod.oval:def:21438Date: (C)2014-10-21   (M)2023-12-07
Class: VULNERABILITYFamily: macos




The Public Key Pinning (PKP) implementation in Mozilla Firefox before 33.0 skips pinning checks upon an unspecified issuer-verification error, which makes it easier for remote attackers to bypass an intended pinning configuration and spoof a web site via a crafted certificate that leads to presentation of the Untrusted Connection dialog to the user.

Platform:
Apple Mac OS 14
Apple Mac OS 13
Apple Mac OS 12
Apple Mac OS 11
Apple Mac OS X 10.15
Apple Mac OS X 10.14
Apple Mac OS X 10.13
Apple Mac OS X 10.11
Apple Mac OS X 10.12
Product:
Mozilla Firefox
Reference:
CVE-2014-1584
CVE    1
CVE-2014-1584
CPE    5
cpe:/a:mozilla:firefox:32.0
cpe:/a:mozilla:firefox:30.0
cpe:/a:mozilla:firefox:31.0
cpe:/a:mozilla:firefox:31.1.0
...

© SecPod Technologies