CVE-2014-8642: Medium severity mozilla seamonkey vulnerability
Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider the id-pkix-ocsp-nocheck extension in deciding whether to trust an OCSP responder, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which there was an incorrect decision to accept a compromised and revoked certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8642?
CVE-2014-8642 is classified as a moderate severity vulnerability that can lead to sensitive information leakage.
How do I fix CVE-2014-8642?
To mitigate CVE-2014-8642, update Mozilla Firefox to version 35.0 or newer, or SeaMonkey to version 2.32 or newer.
What software versions are affected by CVE-2014-8642?
CVE-2014-8642 affects Mozilla Firefox versions before 35.0 and SeaMonkey versions before 2.32, as well as specific openSUSE releases.
What is the impact of CVE-2014-8642?
CVE-2014-8642 can facilitate remote attackers in obtaining sensitive information by exploiting improper trust decisions in OCSP responses.
How can I determine if my system is vulnerable to CVE-2014-8642?
Check your version of Mozilla Firefox or SeaMonkey to see if it is below the specified fixed versions for CVE-2014-8642.