CVE-2014-8639: Medium severity mozilla seamonkey vulnerability
Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Required) status code, which allows remote HTTP proxy servers to conduct session fixation attacks by providing a cookie name that corresponds to the session cookie of the origin server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8639?
CVE-2014-8639 has been classified as a moderate severity vulnerability that can enable session fixation attacks.
How do I fix CVE-2014-8639?
To fix CVE-2014-8639, users should upgrade to Mozilla Firefox version 35.0, Firefox ESR 31.4, Thunderbird 31.4, or SeaMonkey 2.32 or later.
What systems are affected by CVE-2014-8639?
CVE-2014-8639 affects Mozilla Firefox prior to 35.0, Firefox ESR 31.x prior to 31.4, Thunderbird prior to 31.4, and SeaMonkey prior to 2.32.
What type of attack can exploit CVE-2014-8639?
CVE-2014-8639 can be exploited to conduct session fixation attacks through improper handling of Set-Cookie headers.
Is CVE-2014-8639 limited to specific operating systems?
CVE-2014-8639 is not limited to specific operating systems but impacts the software versions listed regardless of the OS.