Vulnerability Name:

CVE-2014-1559 (CCN-94779)

Assigned:2014-07-22
Published:2014-07-22
Updated:2017-01-07
Summary:Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (X.509 certificate parsing outage) via a crafted certificate that does not use UTF-8 character encoding in a required context, a different vulnerability than CVE-2014-1558.

CWE-176: CWE-176: Improper Handling of Unicode Encoding
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2014-1559

Source: SECUNIA
Type: UNKNOWN
60628

Source: CONFIRM
Type: Vendor Advisory
http://www.mozilla.org/security/announce/2014/mfsa2014-65.html

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html

Source: CCN
Type: BID-68815
Mozilla Firefox/Thunderbird CVE-2014-1559 Security Vulnerability

Source: SECTRACK
Type: UNKNOWN
1030619

Source: SECTRACK
Type: UNKNOWN
1030620

Source: CONFIRM
Type: UNKNOWN
https://bugzilla.mozilla.org/show_bug.cgi?id=1026022

Source: XF
Type: UNKNOWN
firefox-cve20141559-weak-security(94779)

Source: GENTOO
Type: UNKNOWN
GLSA-201504-01

Source: CCN
Type: Mozilla Foundation Security Advisory MFSA 2014-65
Certificate parsing broken by non-standard character encoding

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2014-1559

Vulnerable Configuration:Configuration 1:
  • cpe:/a:mozilla:firefox:*:*:*:*:*:*:*:* (Version <= 30.0)
  • OR cpe:/a:mozilla:thunderbird:24.0:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:thunderbird:24.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:thunderbird:24.1:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:thunderbird:24.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:thunderbird:24.2:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:thunderbird:24.3:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:thunderbird:24.4:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:thunderbird:24.5:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:thunderbird:24.6:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:thunderbird:*:*:*:*:*:*:*:* (Version <= 24.7)

  • Configuration CCN 1:
  • cpe:/a:mozilla:firefox_esr:24.6:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:30.0:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:thunderbird:24.6:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:609
    P
    Security update for sqlite3 (Moderate) (in QA)
    2022-10-04
    oval:org.opensuse.security:def:20141559
    V
    CVE-2014-1559
    2022-08-07
    oval:org.opensuse.security:def:1301
    P
    Security update for the Linux Kernel (Live Patch 10 for SLE 15 SP3) (Important)
    2022-04-14
    oval:org.opensuse.security:def:111898
    P
    MozillaFirefox-50.1.0-1.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:945
    P
    Security update for net-snmp (Important)
    2022-01-11
    oval:org.opensuse.security:def:105475
    P
    MozillaFirefox-50.1.0-1.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:48358
    P
    zypper-1.13.51-21.26.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47683
    P
    libXrender1-0.9.8-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48191
    P
    libsmi-0.4.8-18.55 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47266
    P
    glib2-lang-2.48.2-10.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47831
    P
    mutt-1.10.1-55.6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47130
    P
    powerpc-utils-1.3.2-17.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48256
    P
    pam_krb5-2.4.4-4.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47459
    P
    pam_krb5-2.4.4-4.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48045
    P
    ibus-chewing-1.4.14-4.11 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47131
    P
    ppc64-diag-2.7.1-5.6 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48287
    P
    python-pywbem-0.7.0-4.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47591
    P
    dbus-1-1.8.22-29.10.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48129
    P
    libjansson4-2.12-3.5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47145
    P
    rpcbind-0.2.3-21.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:62390
    P
    MozillaFirefox-52.7.3-1.35 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72109
    P
    MozillaFirefox-52.7.3-1.35 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:49332
    P
    socat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49386
    P
    MozillaFirefox on GA media (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:25264
    V
    Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (X.509 certificate parsing outage) via a crafted certificate that does not use UTF-8 character encoding in a required context, a different vulnerability than CVE-2014-1558.
    2014-10-06
    oval:org.mitre.oval:def:25910
    P
    USN-2296-1 -- thunderbird vulnerabilities
    2014-09-15
    oval:org.mitre.oval:def:26037
    P
    SUSE-SU-2014:0960-1 -- Security update for Mozilla Firefox
    2014-09-15
    oval:org.mitre.oval:def:25706
    P
    USN-2295-1 -- firefox vulnerabilities
    2014-09-15
    oval:com.ubuntu.precise:def:20141559000
    V
    CVE-2014-1559 on Ubuntu 12.04 LTS (precise) - low.
    2014-07-23
    oval:com.ubuntu.trusty:def:20141559000
    V
    CVE-2014-1559 on Ubuntu 14.04 LTS (trusty) - low.
    2014-07-23
    BACK
    mozilla firefox *
    mozilla thunderbird 24.0
    mozilla thunderbird 24.0.1
    mozilla thunderbird 24.1
    mozilla thunderbird 24.1.1
    mozilla thunderbird 24.2
    mozilla thunderbird 24.3
    mozilla thunderbird 24.4
    mozilla thunderbird 24.5
    mozilla thunderbird 24.6
    mozilla thunderbird *
    mozilla firefox esr 24.6
    mozilla firefox 30.0
    mozilla thunderbird 24.6