[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-5606Date: (C)2013-11-19   (M)2024-02-22


The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.8
Exploit Score: 8.6
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: NONE
  
Reference:
http://www.securityfocus.com/archive/1/534161/100/0/threaded
BID-63737
DSA-2994
GLSA-201406-19
GLSA-201504-01
RHSA-2013:1791
RHSA-2013:1829
RHSA-2014:0041
SUSE-SU-2013:1807
USN-2030-1
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761
http://www.mozilla.org/security/announce/2013/mfsa2013-103.html
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
http://www.vmware.com/security/advisories/VMSA-2014-0012.html
https://bugzilla.mozilla.org/show_bug.cgi?id=910438
https://developer.mozilla.org/docs/NSS/NSS_3.15.3_release_notes
openSUSE-SU-2013:1732

CPE    3
cpe:/a:mozilla:network_security_services:3.15
cpe:/a:mozilla:network_security_services:3.15.2
cpe:/a:mozilla:network_security_services:3.15.1
CWE    1
CWE-264
OVAL    41
oval:org.secpod.oval:def:109190
oval:org.secpod.oval:def:109185
oval:org.secpod.oval:def:109187
oval:org.secpod.oval:def:701490
...

© SecPod Technologies