Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox HTTP Alternative Services 输入验证漏洞
Vulnerability Description
Mozilla Firefox是美国Mozilla基金会开发的一款开源Web浏览器。 Mozilla Firefox 37.0及之前版本的HTTP Alternative Services实现过程中存在安全漏洞。攻击者可借助Alt-Svc HTTP/2响应头的‘uri-host’字段利用该漏洞实施中间人攻击,绕过SSL服务器的既定的X.509证书验证过程。
CVSS Information
N/A
Vulnerability Type
N/A