Vulnerability Description
Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Required) status code, which allows remote HTTP proxy servers to conduct session fixation attacks by providing a cookie name that corresponds to the session cookie of the origin server.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Seamonkey | <= 2.31 |
| Mozilla | Firefox | <= 34.0.5 |
| Mozilla | Firefox Esr | 31.2 |
| Mozilla | Thunderbird | <= 31.3.0 |
References
- http://linux.oracle.com/errata/ELSA-2015-0046.html
- http://linux.oracle.com/errata/ELSA-2015-0047.html
- http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00032.html
- http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00033.html
- http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00036.html
- http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00002.html
- http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html
- http://lists.opensuse.org/opensuse-updates/2015-01/msg00071.html
- http://rhn.redhat.com/errata/RHSA-2015-0046.html
- http://rhn.redhat.com/errata/RHSA-2015-0047.html
- http://secunia.com/advisories/62237
- http://secunia.com/advisories/62242
- http://secunia.com/advisories/62250
- http://secunia.com/advisories/62253
FAQ
What is CVE-2014-8639?
CVE-2014-8639 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy A...
How severe is CVE-2014-8639?
CVE-2014-8639 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-8639?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Seamonkey, Mozilla Firefox, Mozilla Firefox Esr, Mozilla Thunderbird.