The Public Key Pinning (PKP) implementation in Mozilla Firefox before 33.0 does not properly consider the connection-coalescing behavior of SPDY and HTTP/2 in the case of a shared IP address, which allows man-in-the-middle attackers to bypass an intended pinning configuration and spoof a web site by providing a valid certificate from an arbitrary recognized Certification Authority.
CVSS Details
- CVSS 3.1 Base Score: 6.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firefoxUpgrade linux-firefoxUpgrade seamonkeyUpgrade libxulUpgrade thunderbirdUpgrade linux-thunderbirdUpgrade linux-seamonkeyUpgrade firefox-esr | Dec 10, 2025 | Oct 14, 2014 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird-bin.Upgrade www-client/seamonkey-bin.Upgrade www-client/firefox.Upgrade www-client/firefox-bin.Upgrade www-client/seamonkey.Upgrade dev-libs/nspr.Upgrade mail-client/thunderbird. | Oct 30, 2017 | Oct 15, 2014 |
| Mfsa2014 80 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 33.0 | Oct 16, 2014 | Oct 14, 2014 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.30.0 | Dec 11, 2014 | Oct 15, 2014 |
| Oracle Solaris | — | Upgrade web/browser/firefox to version 38.4.0-0.175.3.8.0.2.0 on Solaris 11.3Upgrade runtime/tcl-8/tcl-sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade database/sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade database/sqlite-3/documentation to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3 | May 29, 2017 | Oct 15, 2014 |
| Suse | — | Upgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox | Dec 18, 2015 | Oct 15, 2014 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Oct 15, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub