Mozilla Firefox NSS Spoofing Vulnerability (CVE-2015-2730)
Mozilla Firefox NSS Spoofing Vulnerability (CVE-2015-2730)
Release date:
Updated on:
Affected Systems:
Mozilla Firefox & lt; 39.0
Mozilla Thunderbird <38.1
Mozilla Firefox ESR <38.1
Description:
CVE (CAN) ID: CVE-2015-2730
Mozilla Firefox is an open-source web browser that uses the Gecko engine.
In versions earlier than Mozilla Firefox 39.0, earlier than Firefox ESR 38.1, and earlier than Thunderbird 38.1, NSS did not correctly execute ECC multiplication. Remote attackers exploit this vulnerability to cheat ECDSA signatures.
<* Source: Watson Ladd
Link: https://www.mozilla.org/en-US/security/advisories/mfsa2015-64/
*>
Suggestion:
Vendor patch:
Mozilla
-------
Mozilla has released a Security Bulletin (mfsa2015-64) and patches for this:
Mfsa2015-64: ECDSA signature validation fails to handle some signatures correctly
Link: https://www.mozilla.org/en-US/security/advisories/mfsa2015-64/
This article permanently updates the link address: