CVE-2014-1490
EPSS 1.6%
Description
Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involving a resumption handshake that triggers incorrect replacement of a session ticket.
How to fix CVE-2014-1490
To remediate CVE-2014-1490, upgrade the affected package to a fixed version below.
- Debian/nss—upgrade to 2:3.15.4-1 or later
Is CVE-2014-1490 being exploited?
Low — EPSS is 1.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2:3.15.4-1