CVE-2025-1014 Details
Description
Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
A vulnerability exists in Mozilla Firefox versions prior to 135, Firefox ESR versions prior to 128.7, and Thunderbird versions prior to 128.7 and in Thunderbird versions prior to 135. This vulnerability arises because the length of certificates was not properly validated when they were added to a certificate store. Although only trusted data was processed, the improper validation could potentially allow for the acceptance of excessively long certificates as valid.
Users can update to Firefox 135, Firefox ESR 128.7, Thunderbird 135, or Thunderbird 128.7 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.debian.org/debian-lts-announce/2025/02/msg00006.html | CVE | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=1940804 | [email protected] | Permissions Required |
| https://www.mozilla.org/security/advisories/mfsa2025-07/ | [email protected] | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2025-09/ | [email protected] | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2025-10/ | [email protected] | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2025-11/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | [email protected] |
| CWE-295 | Improper Certificate Validation | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| mozilla firefox | < 128.7.0 < 135.0 |
CPE
Remediation
| |
| mozilla thunderbird | >= 128.0.1, < 128.7.0 >= 131.0, < 135.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Apr 13, 2026 | CVE Modified | [email protected] |
| Nov 3, 2025 | CVE Modified | CVE |
| Feb 6, 2025 | CVE Modified | CISA-ADP |
| Feb 6, 2025 | Initial Analysis | [email protected] |
| Feb 4, 2025 | New CVE Received | [email protected] |