nss: RSA PKCS#1 signature verification forgery flaw (MFSA 2014-73)
Published Sep 25, 2014
7.5
HIGHCVSS 2.0
EPSS 16.70%
Description
Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.
Affected products
No data.
Configuration 1
Configuration 2
- ≤ 32.0
- 31.0
- 31.1.0
- 32.0.1
- 32.0.2
- 24.8.0
- ≤ 3.16.2.0
- 3.2
- 3.2.1
- 3.3
- 3.3.1
- 3.3.2
- 3.4
- 3.4.1
- 3.4.2
- 3.5
- 3.6
- 3.6.1
- 3.7
- 3.7.1
- 3.7.2
- 3.7.3
- 3.7.5
- 3.7.7
- 3.8
- 3.9
- 3.11.2
- 3.11.3
- 3.11.4
- 3.11.5
- 3.12
- 3.12.1
- 3.12.2
- 3.12.3
- 3.12.3.1
- 3.12.3.2
- 3.12.4
- 3.12.5
- 3.12.6
- 3.12.7
- 3.12.8
- 3.12.9
- 3.12.10
- 3.12.11
- 3.14
- 3.14.1
- 3.14.2
- 3.14.3
- 3.14.4
- 3.14.5
- 3.15
- 3.15.1
- 3.15.2
- 3.15.3
- 3.15.3.1
- 3.15.4
- 3.15.5
- 3.16
- 3.16.1
- 3.16.3
- 3.16.4
- n/a
- ≤ 2.29
- 1.0
- 1.0
- 1.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.0.5
- 1.0.6
- 1.0.7
- 1.0.8
- 1.0.9
- 1.1
- 1.1
- 1.1
- 1.1.1
- 1.1.2
- 1.1.3
- 1.1.4
- 1.1.5
- 1.1.6
- 1.1.7
- 1.1.8
- 1.1.9
- 1.1.10
- 1.1.11
- 1.1.12
- 1.1.13
- 1.1.14
- 1.1.15
- 1.1.16
- 1.1.17
- 1.1.18
- 1.1.19
- 1.5.0.8
- 1.5.0.9
- 1.5.0.10
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0.1
- 2.0.2
- 2.0.3
- 2.0.4
- 2.0.5
- 2.0.6
- 2.0.7
- 2.0.8
- 2.0.9
- 2.0.10
- 2.0.11
- 2.0.12
- 2.0.13
- 2.0.14
- 2.1
- 2.1
- 2.1
- 2.1
- 2.1
- 2.1
- 2.1
- 2.1
- 2.1
- 2.2
- 2.2
- 2.2
- 2.2
- 2.10
- 2.10
- 2.10
- 2.10
- 2.10.1
- 2.11
- 2.11
- 2.11
- 2.11
- 2.11
- 2.11
- 2.11
- 2.12
- 2.12
- 2.12
- 2.12
- 2.12
- 2.12
- 2.12
- 2.12.1
- 2.13
- 2.13
- 2.13
- 2.13
- 2.13
- 2.13
- 2.13
- 2.13.1
- 2.13.2
- 2.14
- 2.14
- 2.14
- 2.14
- 2.14
- 2.14
- 2.15
- 2.15
- 2.15
- 2.15
- 2.15
- 2.15
- 2.15
- 2.15.1
- 2.15.2
- 2.16
- 2.16
- 2.16
- 2.16
- 2.16
- 2.16
- 2.16.1
- 2.16.2
- 2.17
- 2.17
- 2.17
- 2.17
- 2.17
- 2.17.1
- 2.18
- 2.18
- 2.18
- 2.18
- 2.19
- 2.19
- 2.19
- 2.20
- 2.20
- 2.20
- 2.20
- 2.21
- 2.21
- 2.22
- 2.22
- 2.22.1
- 2.23
- 2.23
- 2.24
- 2.24
- 2.25
- 2.25
- 2.25
- 2.25
- 2.26
- 2.26
- ≤ 24.8.0
- 31.0
- 31.1.0
- 31.1.1
Configuration 3
No data.
RHEV Manager version 3.4
rhev-hypervisor6-0:6.5-20140930.1.el6ev
Fixed · RHSA-2014:1354
Red Hat Enterprise Linux 4 Extended Lifecycle Support
nss-0:3.12.10-10.el4
Fixed · RHSA-2014:1371
Red Hat Enterprise Linux 5
nss-0:3.16.1-4.el5_11
Fixed · RHSA-2014:1307
Red Hat Enterprise Linux 5.6 Long Life
nss-0:3.12.8-10.el5_6
Fixed · RHSA-2014:1371
Red Hat Enterprise Linux 5.9 Extended Update Support
nss-0:3.14.3-10.el5_9
Fixed · RHSA-2014:1371
Red Hat Enterprise Linux 6
nss-0:3.16.1-7.el6_5
Fixed · RHSA-2014:1307
Red Hat Enterprise Linux 6
nss-softokn-0:3.14.3-12.el6_5
Fixed · RHSA-2014:1307
Red Hat Enterprise Linux 6
nss-util-0:3.16.1-2.el6_5
Fixed · RHSA-2014:1307
Red Hat Enterprise Linux 6.2 Advanced Update Support
nss-0:3.13.1-11.el6_2
Fixed · RHSA-2014:1371
Red Hat Enterprise Linux 6.2 Advanced Update Support
nss-softokn-0:3.12.9-12.el6_2
Fixed · RHSA-2014:1371
Red Hat Enterprise Linux 6.2 Advanced Update Support
nss-util-0:3.13.1-6.el6_2
Fixed · RHSA-2014:1371
Red Hat Enterprise Linux 6.4 Extended Update Support
nss-0:3.14.3-8.el6_4
Fixed · RHSA-2014:1371
Red Hat Enterprise Linux 6.4 Extended Update Support
nss-softokn-0:3.14.3-4.el6_4
Fixed · RHSA-2014:1371
Red Hat Enterprise Linux 6.4 Extended Update Support
nss-util-0:3.14.3-4.el6_4
Fixed · RHSA-2014:1371
Red Hat Enterprise Linux 7
nss-0:3.16.2-7.el7_0
Fixed · RHSA-2014:1307
Red Hat Enterprise Linux 7
nss-softokn-0:3.16.2-2.el7_0
Fixed · RHSA-2014:1307
Red Hat Enterprise Linux 7
nss-util-0:3.16.2-2.el7_0
Fixed · RHSA-2014:1307
| Product | Package | State | Advisory |
|---|---|---|---|
| RHEV Manager version 3.4 | rhev-hypervisor6-0:6.5-20140930.1.el6ev | Fixed | RHSA-2014:1354 |
| Red Hat Enterprise Linux 4 Extended Lifecycle Support | nss-0:3.12.10-10.el4 | Fixed | RHSA-2014:1371 |
| Red Hat Enterprise Linux 5 | nss-0:3.16.1-4.el5_11 | Fixed | RHSA-2014:1307 |
| Red Hat Enterprise Linux 5.6 Long Life | nss-0:3.12.8-10.el5_6 | Fixed | RHSA-2014:1371 |
| Red Hat Enterprise Linux 5.9 Extended Update Support | nss-0:3.14.3-10.el5_9 | Fixed | RHSA-2014:1371 |
| Red Hat Enterprise Linux 6 | nss-0:3.16.1-7.el6_5 | Fixed | RHSA-2014:1307 |
| Red Hat Enterprise Linux 6 | nss-softokn-0:3.14.3-12.el6_5 | Fixed | RHSA-2014:1307 |
| Red Hat Enterprise Linux 6 | nss-util-0:3.16.1-2.el6_5 | Fixed | RHSA-2014:1307 |
| Red Hat Enterprise Linux 6.2 Advanced Update Support | nss-0:3.13.1-11.el6_2 | Fixed | RHSA-2014:1371 |
| Red Hat Enterprise Linux 6.2 Advanced Update Support | nss-softokn-0:3.12.9-12.el6_2 | Fixed | RHSA-2014:1371 |
| Red Hat Enterprise Linux 6.2 Advanced Update Support | nss-util-0:3.13.1-6.el6_2 | Fixed | RHSA-2014:1371 |
| Red Hat Enterprise Linux 6.4 Extended Update Support | nss-0:3.14.3-8.el6_4 | Fixed | RHSA-2014:1371 |
| Red Hat Enterprise Linux 6.4 Extended Update Support | nss-softokn-0:3.14.3-4.el6_4 | Fixed | RHSA-2014:1371 |
| Red Hat Enterprise Linux 6.4 Extended Update Support | nss-util-0:3.14.3-4.el6_4 | Fixed | RHSA-2014:1371 |
| Red Hat Enterprise Linux 7 | nss-0:3.16.2-7.el7_0 | Fixed | RHSA-2014:1307 |
| Red Hat Enterprise Linux 7 | nss-softokn-0:3.16.2-2.el7_0 | Fixed | RHSA-2014:1307 |
| Red Hat Enterprise Linux 7 | nss-util-0:3.16.2-2.el7_0 | Fixed | RHSA-2014:1307 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (44 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 16.70% (0.16703) | 96.94th | v5 (v2026.06.15) |
| Jun 15, 2026 | 17.00% (0.17004) | 96.67th | v5 (v2026.06.15) |
| May 11, 2026 | 33.60% (0.33600) | 96.97th | v4 (v2025.03.14) |
| Apr 4, 2026 | 30.94% (0.30935) | 96.72th | v4 (v2025.03.14) |
| Mar 12, 2026 | 34.44% (0.34437) | 96.93th | v4 (v2025.03.14) |
| Mar 3, 2026 | 36.84% (0.36836) | 97.09th | v4 (v2025.03.14) |
| Jan 1, 2026 | 40.04% (0.40040) | 97.21th | v4 (v2025.03.14) |
| Dec 25, 2025 | 46.21% (0.46212) | 97.52th | v4 (v2025.03.14) |
| Dec 23, 2025 | 40.04% (0.40040) | 97.18th | v4 (v2025.03.14) |
| Dec 22, 2025 | 46.21% (0.46212) | 97.52th | v4 (v2025.03.14) |
| Dec 16, 2025 | 40.04% (0.40040) | 97.17th | v4 (v2025.03.14) |
| Dec 13, 2025 | 46.21% (0.46212) | 97.51th | v4 (v2025.03.14) |
| Dec 10, 2025 | 40.04% (0.40040) | 97.17th | v4 (v2025.03.14) |
| Dec 3, 2025 | 35.83% (0.35828) | 96.92th | v4 (v2025.03.14) |
| Nov 3, 2025 | 36.84% (0.36836) | 96.97th | v4 (v2025.03.14) |
| Nov 1, 2025 | 42.95% (0.42945) | 97.35th | v4 (v2025.03.14) |
| Oct 31, 2025 | 36.84% (0.36836) | 96.96th | v4 (v2025.03.14) |
| Oct 29, 2025 | 42.95% (0.42945) | 97.32th | v4 (v2025.03.14) |
| Oct 28, 2025 | 36.84% (0.36836) | 96.95th | v4 (v2025.03.14) |
| Oct 27, 2025 | 42.95% (0.42945) | 97.34th | v4 (v2025.03.14) |
| Oct 24, 2025 | 36.84% (0.36836) | 96.95th | v4 (v2025.03.14) |
| Oct 22, 2025 | 42.95% (0.42945) | 97.31th | v4 (v2025.03.14) |
| Oct 21, 2025 | 36.84% (0.36836) | 96.93th | v4 (v2025.03.14) |
| Oct 20, 2025 | 42.95% (0.42945) | 97.31th | v4 (v2025.03.14) |
| Oct 19, 2025 | 36.84% (0.36836) | 96.93th | v4 (v2025.03.14) |
| Oct 17, 2025 | 42.95% (0.42945) | 97.31th | v4 (v2025.03.14) |
| Oct 16, 2025 | 36.84% (0.36836) | 96.94th | v4 (v2025.03.14) |
| Oct 14, 2025 | 42.95% (0.42945) | 97.31th | v4 (v2025.03.14) |
| Oct 1, 2025 | 35.36% (0.35358) | 96.94th | v4 (v2025.03.14) |
| Jul 22, 2025 | 42.01% (0.42007) | 97.29th | v4 (v2025.03.14) |
| Jul 16, 2025 | 46.42% (0.46417) | 97.52th | v4 (v2025.03.14) |
| May 7, 2025 | 38.39% (0.38385) | 97.02th | v4 (v2025.03.14) |
| Mar 30, 2025 | 41.97% (0.41967) | 97.16th | v4 (v2025.03.14) |
| Mar 29, 2025 | 68.48% (0.68476) | 98.09th | v4 (v2025.03.14) |
| Mar 23, 2025 | 41.97% (0.41967) | 97.03th | v4 (v2025.03.14) |
| Mar 17, 2025 | 38.87% (0.38866) | 96.92th | v4 (v2025.03.14) |
| Dec 12, 2024 | 3.76% (0.03762) | 92.17th | v3 (v2023.03.01) |
| May 7, 2024 | 3.76% (0.03762) | 91.77th | v3 (v2023.03.01) |
| Dec 10, 2023 | 4.40% (0.04400) | 91.46th | v3 (v2023.03.01) |
| Jun 2, 2023 | 6.10% (0.06100) | 92.42th | v3 (v2023.03.01) |
| Mar 7, 2023 | 6.73% (0.06735) | 92.71th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.36% (0.04358) | 88.02th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.36% (0.04358) | 86.83th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.36% (0.04358) | 70.59th | v2 (v2022.01.01) |
References (38)
- http://googlechromereleases.blogspot.com/2014/09/stable-channel-update-for-chrome-os_24.html x_refsource_CONFIRM
- http://googlechromereleases.blogspot.com/2014/09/stable-channel-update_24.html x_refsource_CONFIRM
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698 x_refsource_CONFIRM
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761 x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00032.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00036.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00039.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2014-1307.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2014-1354.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2014-1371.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/61540 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61574 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61575 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61576 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/61583 third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2014/dsa-3033 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2014/dsa-3034 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2014/dsa-3037 vendor-advisoryx_refsource_DEBIAN
- http://www.kb.cert.org/vuls/id/772676 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.mozilla.org/security/announce/2014/mfsa2014-73.html x_refsource_CONFIRMVendor Advisory
- http://www.novell.com/support/kb/doc.php?id=7015701 x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html x_refsource_CONFIRM
- http://www.securityfocus.com/bid/70116 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-2360-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2360-2 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2361-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2014-1568 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1064636 x_refsource_CONFIRM
- https://bugzilla.mozilla.org/show_bug.cgi?id=1069405 x_refsource_CONFIRMVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1145429 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96194 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2014-1568
- https://security.gentoo.org/glsa/201504-01 vendor-advisoryx_refsource_GENTOO
- https://www.cve.org/CVERecord?id=CVE-2014-1568
Change history (0)
No recorded changes yet.