Lucene search

K
mozillaMozilla FoundationMFSA2014-45
HistoryApr 29, 2014 - 12:00 a.m.

Incorrect IDNA domain name matching for wildcard certificates — Mozilla

2014-04-2900:00:00
Mozilla Foundation
www.mozilla.org
18

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.002 Low

EPSS

Percentile

53.1%

Security researcher Christian Heimes reported that the Network Security Services (NSS) library does not handle IDNA domain prefixes according to RFC 6125 for wildcard certificates. This leads to improper wildcard matching of domains when they should not be matched in compliance with the specification. This issue was fixed in NSS version 3.16.

Affected configurations

Vulners
Node
mozillafirefoxRange<29
OR
mozillaseamonkeyRange<2.26
CPENameOperatorVersion
firefoxlt29
seamonkeylt2.26

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.002 Low

EPSS

Percentile

53.1%