CVE-2015-0832: Medium severity opensuse vulnerability
Mozilla Firefox before 36.0 does not properly recognize the equivalence of domain names with and without a trailing . (dot) character, which allows man-in-the-middle attackers to bypass the HPKP and HSTS protection mechanisms by constructing a URL with this character and leveraging access to an X.509 certificate for a domain with this character.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0832?
CVE-2015-0832 has been classified as a moderate severity vulnerability.
How do I fix CVE-2015-0832?
To fix CVE-2015-0832, update to Mozilla Firefox version 36.0 or later.
What types of attacks does CVE-2015-0832 allow?
CVE-2015-0832 allows man-in-the-middle attackers to bypass HPKP and HSTS protection mechanisms.
On which platforms is CVE-2015-0832 applicable?
CVE-2015-0832 affects multiple versions of Mozilla Firefox on various platforms and operating systems.
How can I check if I'm vulnerable to CVE-2015-0832?
You can check if you're vulnerable to CVE-2015-0832 by verifying your current version of Mozilla Firefox against the patched versions.