Status
Justification
Impact
Firefox claimed on September 27, 2011 that Firefox itself is not vulnerable to this attack. While Firefox does use TLS 1.0 (the version of TLS with this weakness), the technical details of the attack require the ability to completely control the content of connections originating in the browser which Firefox does not allow. More details can be found here: https://blog.mozilla.org/security/2011/09/27/attack-against-tls-protected-communications/
Status