Denial of Service Vulnerability in Mozilla Firefox and SeaMonkey
CVE-2014-1498
Currently unrated
Key Information:
- Vendor
Suse
- Vendor
- CVE Published:
- 19 March 2014
What is CVE-2014-1498?
The vulnerability resides in the crypto.generateCRMFRequest method of Mozilla Firefox versions prior to 28.0 and SeaMonkey versions before 2.25. This issue arises from improper validation of a specific key type, which can allow attackers to trigger application crashes. Through maliciously crafted vectors that prompt the generation of keys potentially supporting the Elliptic Curve ec-dual-use algorithm, remote attackers can exploit this flaw to disrupt the normal functionality of the affected applications, leading to a denial of service.