Download Firefox

Firefox is no longer supported on Windows 8.1 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox is no longer supported on macOS 10.14 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox Privacy Notice

Mozilla Foundation Security Advisory 2014-18

crypto.generateCRMFRequest does not validate type of key

Announced
March 18, 2014
Reporter
David Keeler
Impact
Low
Products
Firefox, SeaMonkey
Fixed in
  • Firefox 28
  • SeaMonkey 2.25

Description

Mozilla developer David Keeler reported that the crypto.generateCRFMRequest method did not correctly validate the key type of the KeyParams argument when generating ec-dual-use requests. This could lead to a crash and a denial of service (DOS) attack.

References