CVE-2014-1569
Summary
| CVE | CVE-2014-1569 |
|---|---|
| State | PUBLISHED |
| Assigner | mozilla |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-12-15 18:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The definite_length_decoder function in lib/util/quickder.c in Mozilla Network Security Services (NSS) before 3.16.2.4 and 3.17.x before 3.17.3 does not ensure that the DER encoding of an ASN.1 length is properly formed, which allows remote attackers to conduct data-smuggling attacks by using a long byte sequence for an encoding, as demonstrated by the SEC_QuickDERDecodeItem function's improper handling of an arbitrary-length encoding of 0x00. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Network Security Services | 3.16.2.0 | All | All | All |
| Application | Mozilla | Network Security Services | 3.16.2.1 | All | All | All |
| Application | Mozilla | Network Security Services | 3.16.2.2 | All | All | All |
| Application | Mozilla | Network Security Services | 3.17.0 | All | All | All |
| Application | Mozilla | Network Security Services | 3.17.1 | All | All | All |
| Application | Mozilla | Network Security Services | 3.17.2 | All | All | All |
| Application | Mozilla | Network Security Services | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Hardware-Enabled Security | af854a3a-2127-422b-91ae-364da2661108 | www.intelsecurity.com | Exploit |
| [security-announce] SUSE-SU-2015:0180-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| ImperialViolet - PKCS#1 signature validation | af854a3a-2127-422b-91ae-364da2661108 | www.imperialviolet.org | Exploit |
| benmmurphy comments on RSA Signature Forgery in NSS | af854a3a-2127-422b-91ae-364da2661108 | www.reddit.com | Exploit |
| Oracle Critical Patch Update - July 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| [security-announce] openSUSE-SU-2015:0404-1: important: Security update | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| [security-announce] SUSE-SU-2015:0171-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Oracle Critical Patch Update - October 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Debian -- Security Information -- DSA-3186-1 nss | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| 1064670 – (CVE-2014-1569) ASN.1 DER decoding of lengths is too permissive, allowing undetected smuggling of arbitrary data | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | Exploit |
| [security-announce] SUSE-SU-2015:0173-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Oracle Communications Applications Flaws Let Remote Users Gain Elevated Privileges and Partially Access Data, Modify Data, and Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| NSS 3.17.3 release notes - Mozilla | MDN | af854a3a-2127-422b-91ae-364da2661108 | developer.mozilla.org | Vendor Advisory |
| [security-announce] openSUSE-SU-2015:0138-1: important: Firefox update t | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Oracle Solaris Bulletin - April 2016 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.