MEDIUM · 4.3

CVE-2015-0799

The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that...

Vulnerability Description

The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
CanonicalUbuntu Linux12.04
OpensuseOpensuse13.1
MozillaFirefox<= 37.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-0799?

CVE-2015-0799 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that...

How severe is CVE-2015-0799?

CVE-2015-0799 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-0799?

Check the references section above for vendor advisories and patch information. Affected products include: Canonical Ubuntu Linux, Opensuse Opensuse, Mozilla Firefox.