Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involving a resumption handshake that triggers incorrect replacement of a session ticket.
References
Link Providers
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761 cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/127966.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129218.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00010.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00017.html cve-icon cve-icon
http://osvdb.org/102876 cve-icon cve-icon
http://seclists.org/fulldisclosure/2014/Dec/23 cve-icon cve-icon
http://secunia.com/advisories/56706 cve-icon cve-icon
http://secunia.com/advisories/56767 cve-icon cve-icon
http://secunia.com/advisories/56787 cve-icon cve-icon
http://secunia.com/advisories/56858 cve-icon cve-icon
http://secunia.com/advisories/56888 cve-icon cve-icon
http://secunia.com/advisories/56922 cve-icon cve-icon
http://www.debian.org/security/2014/dsa-2858 cve-icon cve-icon
http://www.mozilla.org/security/announce/2014/mfsa2014-12.html cve-icon cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/534161/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/65335 cve-icon cve-icon
http://www.securitytracker.com/id/1029717 cve-icon cve-icon
http://www.securitytracker.com/id/1029720 cve-icon cve-icon
http://www.securitytracker.com/id/1029721 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-2102-1 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-2102-2 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-2119-1 cve-icon cve-icon
http://www.vmware.com/security/advisories/VMSA-2014-0012.html cve-icon cve-icon
https://8pecxstudios.com/?page_id=44080 cve-icon cve-icon
https://bugzilla.mozilla.org/show_bug.cgi?id=930857 cve-icon cve-icon
https://bugzilla.mozilla.org/show_bug.cgi?id=930874 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/90885 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2014-1490 cve-icon
https://security.gentoo.org/glsa/201504-01 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2014-1490 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2014-02-06T02:00:00

Updated: 2024-08-06T09:42:36.290Z

Reserved: 2014-01-16T00:00:00

Link: CVE-2014-1490

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2014-02-06T05:44:25.097

Modified: 2024-02-14T01:17:43.863

Link: CVE-2014-1490

cve-icon Redhat

Severity : Moderate

Publid Date: 2014-02-04T00:00:00Z

Links: CVE-2014-1490 - Bugzilla