CVE Vulnerabilities

CVE-2010-3170

Published: Oct 21, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
2.6 LOW
AV:N/AC:H/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 recognize a wildcard IP address in the subjects Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla3.6 (including)3.6 (including)
FirefoxMozilla3.6.2 (including)3.6.2 (including)
FirefoxMozilla3.6.3 (including)3.6.3 (including)
FirefoxMozilla3.6.4 (including)3.6.4 (including)
FirefoxMozilla3.6.6 (including)3.6.6 (including)
FirefoxMozilla3.6.7 (including)3.6.7 (including)
FirefoxMozilla3.6.8 (including)3.6.8 (including)
FirefoxMozilla3.6.9 (including)3.6.9 (including)
FirefoxMozilla3.6.10 (including)3.6.10 (including)
Red Hat Enterprise Linux 3RedHatseamonkey-0:1.0.9-0.61.el3*
Red Hat Enterprise Linux 4RedHatseamonkey-0:1.0.9-64.el4*
Red Hat Enterprise Linux 4RedHatfirefox-0:3.6.11-2.el4*
Red Hat Enterprise Linux 4RedHatnss-0:3.12.8-1.el4*
Red Hat Enterprise Linux 5RedHatfirefox-0:3.6.11-2.el5*
Red Hat Enterprise Linux 5RedHatnss-0:3.12.8-1.el5*
Red Hat Enterprise Linux 5RedHatxulrunner-0:1.9.2.11-2.el5*
Red Hat Enterprise Linux 6RedHatnss-0:3.12.8-1.el6_0*
Red Hat Enterprise Linux 6RedHatnss-softokn-0:3.12.8-1.el6_0*
Red Hat Enterprise Linux 6RedHatnss-util-0:3.12.8-1.el6_0*
NsprUbuntuupstream*
NssUbuntudevel*
NssUbuntuhardy*
NssUbuntujaunty*
NssUbuntukarmic*
NssUbuntulucid*
NssUbuntumaverick*
NssUbuntuupstream*

References