Release date:
Updated on:
Affected Systems:
Mozilla Firefox & lt; 28.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 66421
CVE (CAN) ID: CVE-2014-1498
Firefox is a very popular open-source WEB browser. Thunderbird is a mail client that supports IMAP, POP protocol, and HTML format.
Earlier versions of Mozilla Firefox 28.0, earlier versions of Firefox ESR 24.4, earlier versions of Thunderbird 24.4, and earlier versions of SeaMonkey 2.25. the generateCRMFRequest method does not correctly verify a key type, which can cause a remote attacker to cause a denial of service.
<* Source: David Keeler
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Mozilla
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.mozilla.org/security/
Http://www.mozilla.org/security/announce/2014/mfsa2014-18.html