CVE-2014-1498: Medium severity SUSE Linux Enterprise Desktop vulnerability
The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not properly validate a certain key type, which allows remote attackers to cause a denial of service (application crash) via vectors that trigger generation of a key that supports the Elliptic Curve ec-dual-use algorithm.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1498?
CVE-2014-1498 has a severity rating of medium, as it can cause a denial of service through application crashes.
How do I fix CVE-2014-1498?
To fix CVE-2014-1498, update Mozilla Firefox to version 28.0 or higher and SeaMonkey to version 2.25 or higher.
Which versions are affected by CVE-2014-1498?
CVE-2014-1498 affects Mozilla Firefox versions before 28.0 and SeaMonkey versions before 2.25.
What kind of attack does CVE-2014-1498 enable?
CVE-2014-1498 enables remote attackers to trigger application crashes, leading to a denial of service.
Is CVE-2014-1498 exploitable from remote locations?
Yes, CVE-2014-1498 can be exploited remotely, allowing attackers to cause denial of service without physical access.