CVE Vulnerabilities

CVE-2010-3173

Published: Oct 21, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
5.1 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly set the minimum key length for Diffie-Hellman Ephemeral (DHE) mode, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla3.6 (including)3.6 (including)
FirefoxMozilla3.6.2 (including)3.6.2 (including)
FirefoxMozilla3.6.3 (including)3.6.3 (including)
FirefoxMozilla3.6.4 (including)3.6.4 (including)
FirefoxMozilla3.6.6 (including)3.6.6 (including)
FirefoxMozilla3.6.7 (including)3.6.7 (including)
FirefoxMozilla3.6.8 (including)3.6.8 (including)
FirefoxMozilla3.6.9 (including)3.6.9 (including)
FirefoxMozilla3.6.10 (including)3.6.10 (including)
Red Hat Enterprise Linux 3RedHatseamonkey-0:1.0.9-0.61.el3*
Red Hat Enterprise Linux 4RedHatseamonkey-0:1.0.9-64.el4*
Red Hat Enterprise Linux 4RedHatfirefox-0:3.6.11-2.el4*
Red Hat Enterprise Linux 4RedHatnss-0:3.12.8-1.el4*
Red Hat Enterprise Linux 5RedHatfirefox-0:3.6.11-2.el5*
Red Hat Enterprise Linux 5RedHatnss-0:3.12.8-1.el5*
Red Hat Enterprise Linux 5RedHatxulrunner-0:1.9.2.11-2.el5*
NsprUbuntuupstream*
NssUbuntudevel*
NssUbuntuhardy*
NssUbuntujaunty*
NssUbuntukarmic*
NssUbuntulucid*
NssUbuntumaverick*
NssUbuntuupstream*

References