CVE-2015-0834: Infoleak
The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0834?
CVE-2015-0834 has a medium severity rating, as it allows man-in-the-middle attackers to intercept credentials.
How do I fix CVE-2015-0834?
To fix CVE-2015-0834, update to a version of Mozilla Firefox above 36.0 which utilizes TLS for TURN and STUN server access.
Which versions of Mozilla Firefox are affected by CVE-2015-0834?
CVE-2015-0834 affects all versions of Mozilla Firefox prior to 36.0.
What is CVE-2015-0834 about?
CVE-2015-0834 describes a vulnerability in the WebRTC subsystem of Mozilla Firefox that allows unencrypted access to TURN and STUN servers.
Is CVE-2015-0834 specific to any operating system?
No, CVE-2015-0834 applies to Mozilla Firefox regardless of the operating system.