Bug 35993

Summary: Firefox: Signature forgery (3.2)
Product: UCS Reporter: Moritz Muehlenhoff <jmm>
Component: Security updatesAssignee: Janek Walkenhorst <walkenhorst>
Status: CLOSED FIXED QA Contact: Felix Botner <botner>
Severity: normal    
Priority: P2 CC: walkenhorst
Version: UCS 3.2   
Target Milestone: UCS 3.2-3-errata   
Hardware: Other   
OS: Linux   
What kind of report is it?: --- What type of bug is this?: ---
Who will be affected by this bug?: --- How will those affected feel about the bug?: ---
User Pain: Enterprise Customer affected?:
School Customer affected?: ISV affected?:
Waiting Support: Flags outvoted (downgraded) after PO Review:
Ticket number: Bug group (optional):
Max CVSS v3 score:

Description Moritz Muehlenhoff univentionstaff 2014-09-24 22:07:15 CEST
CVE-2014-1568

Incorrect parsing of ASN1 values can lead to the forgery of RSA certificates.

This is fixed in 24.8.1
Comment 1 Janek Walkenhorst univentionstaff 2014-09-25 18:34:43 CEST
Tests (amd64): OK
Advisory: 2014-09-25-firefox-{de,en}.yaml
Comment 2 Felix Botner univentionstaff 2014-09-26 09:11:16 CEST
OK - amd64/i386 firefox-{de,en}

OK - YAML