CVE-2014-1584
15.10.2014, 10:55
The Public Key Pinning (PKP) implementation in Mozilla Firefox before 33.0 skips pinning checks upon an unspecified issuer-verification error, which makes it easier for remote attackers to bypass an intended pinning configuration and spoof a web site via a crafted certificate that leads to presentation of the Untrusted Connection dialog to the user.Enginsight
Vendor | Product | Version |
---|---|---|
mozilla | firefox | 𝑥 ≤ 32.0 |
mozilla | firefox | 30.0 |
mozilla | firefox | 31.0 |
mozilla | firefox | 31.1.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References