Revision Date: | 2015-08-03 | Version: | 22 | Title: | Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involving a resumption handshake that triggers incorrect replacement of a session ticket | Description: | Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involving a resumption handshake that triggers incorrect replacement of a session ticket. | Family: | windows | Class: | vulnerability | Status: | ACCEPTED | Reference(s): | CVE-2014-1490
| Platform(s): | Microsoft Windows 2000 Microsoft Windows 7 Microsoft Windows 8 Microsoft Windows Server 2003 Microsoft Windows Vista Microsoft Windows XP
| Product(s): | Mozilla Firefox Mozilla Firefox ESR Mozilla SeaMonkey Mozilla Thunderbird
| Definition Synopsis | Check for vulnerable Firefox Mozilla Firefox Mainline release is installed
AND Mozilla Network Security Services before 3.15.4 in Mozilla Firefox
OR Check for vulnerable Seamonkey
Mozilla Seamonkey is installed
AND Mozilla Network Security Services before 3.15.4 in Mozilla Seamonkey
OR Check for vulnerable Thunderbird
Mozilla Thunderbird Mainline release is installed
AND Mozilla Network Security Services before 3.15.4 in Mozilla Thunderbird
OR Related to Mozilla Firefox Mainline
Mozilla Firefox Mainline release is installed
AND Mozilla Firefox Mainline version less than 27.0
OR Related to Mozilla Firefox ESR
Mozilla Firefox ESR is installed
AND Mozilla Firefox ESR version less than 24.3 and greater than 24.0
OR Related to Mozilla SeaMonkey
Mozilla Seamonkey is installed
AND Mozilla Seamonkey version less than 2.24
OR Related to Mozilla Thunderbird Mainline
Mozilla Thunderbird Mainline release is installed
AND Check if the Mozilla Thunderbird version is less than 24.3
|
|