Fedora Account System
Red Hat Associate
Red Hat Customer
Mozilla developer David Keeler reported that the crypto.generateCRFMRequest method did not correctly validate the key type of the KeyParams argument when generating ec-dual-use requests. This could lead to a crash and a denial of service (DOS) attack. External Reference: http://www.mozilla.org/security/announce/2014/mfsa2014-18.html Acknowledgements: Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges David Keeler as the original reporter. Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5 and 6