~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2014-1490

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDateAtUSN: 2014-02-05
2
 
Candidate: CVE-2014-1490
3
 
PublicDate: 2014-02-06
4
 
References: 
5
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1490
6
 
 http://www.mozilla.org/security/announce/2014/mfsa2014-12.html
7
 
 https://usn.ubuntu.com/usn/usn-2102-1
8
 
 https://usn.ubuntu.com/usn/usn-2119-1
9
 
Description:
10
 
 Race condition in libssl in Mozilla Network Security Services (NSS) before
11
 
 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before
12
 
 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products,
13
 
 allows remote attackers to cause a denial of service (use-after-free) or
14
 
 possibly have unspecified other impact via vectors involving a resumption
15
 
 handshake that triggers incorrect replacement of a session ticket.
16
 
Ubuntu-Description: 
17
 
Notes: 
18
 
Bugs: 
19
 
Priority: medium
20
 
Discovered-by:
21
 
Assigned-to: chrisccoulson
22
 
 
23
 
Patches_firefox:
24
 
upstream_firefox: released (27.0)
25
 
lucid_firefox: ignored (reached end-of-life)
26
 
precise_firefox: released (27.0+build1-0ubuntu0.12.04.1)
27
 
quantal_firefox: released (27.0+build1-0ubuntu0.12.10.1)
28
 
saucy_firefox: released (27.0+build1-0ubuntu0.13.10.1)
29
 
devel_firefox: not-affected
30
 
 
31
 
Patches_thunderbird:
32
 
upstream_thunderbird: released (24.3.0)
33
 
lucid_thunderbird: ignored (reached end-of-life)
34
 
precise_thunderbird: released (1:24.3.0+build2-0ubuntu0.12.04.1)
35
 
quantal_thunderbird: released (1:24.3.0+build2-0ubuntu0.12.10.1)
36
 
saucy_thunderbird: released (1:24.3.0+build2-0ubuntu0.13.10.1)
37
 
devel_thunderbird: released (1:24.4.0+build1-0ubuntu1)
38
 
 
39
 
Patches_nss:
40
 
upstream_nss: released (3.15.4)
41
 
lucid_nss: not-affected
42
 
precise_nss: not-affected
43
 
quantal_nss: not-affected
44
 
saucy_nss: not-affected
45
 
devel_nss: not-affected