Race Condition in libssl of Mozilla Products Leading to Denial of Service
CVE-2014-1490
Currently unrated
Key Information:
- Vendor
Mozilla
- Vendor
- CVE Published:
- 6 February 2014
What is CVE-2014-1490?
The vulnerability in libssl of Mozilla's Network Security Services (NSS) pre-3.15.4 can be exploited via a race condition during session ticket replacement in resumption handshakes. This flaw may allow remote attackers to induce a denial of service, resulting in a use-after-free situation, and could potentially lead to other unintentional impacts on affected systems. Ensuring timely updates and patches is critical for mitigating risks associated with this vulnerability.
References
Timeline
Vulnerability published
Vulnerability Reserved