Race Condition in libssl of Mozilla Products Leading to Denial of Service
CVE-2014-1490

Currently unrated

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
6 February 2014

What is CVE-2014-1490?

The vulnerability in libssl of Mozilla's Network Security Services (NSS) pre-3.15.4 can be exploited via a race condition during session ticket replacement in resumption handshakes. This flaw may allow remote attackers to induce a denial of service, resulting in a use-after-free situation, and could potentially lead to other unintentional impacts on affected systems. Ensuring timely updates and patches is critical for mitigating risks associated with this vulnerability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.