Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Network Security Services 安全漏洞
Vulnerability Description
Mozilla Network Security Services(NSS)是美国Mozilla基金会开发的一个函数库(网络安全服务库),它可跨平台提供SSL、S/MIME和其他Internet安全标准支持。 多款Mozilla产品和基于Windows或OS X平台的Google Chrome和Google Chrome OS上使用的Mozilla NSS中存在安全漏洞,该漏洞源于程序没有正确解析X.509证书中的ASN.1值。远程者可通过特制的证书利用该漏洞伪造RSA签名。以下版本受到影响:Mozill
CVSS Information
N/A
Vulnerability Type
N/A