CVE Vulnerabilities

CVE-2011-5094

Published: Jun 16, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Mozilla Network Security Services (NSS) 3.x, with certain settings of the SSL_ENABLE_RENEGOTIATION option, does not properly restrict client-initiated renegotiation within the SSL and TLS protocols, which might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection, a different vulnerability than CVE-2011-1473. NOTE: it can also be argued that it is the responsibility of server deployments, not a security library, to prevent or limit renegotiation when it is inappropriate within a specific environment

Affected Software

NameVendorStart VersionEnd Version
Network_security_servicesMozilla3.2 (including)3.2 (including)
Network_security_servicesMozilla3.2.1 (including)3.2.1 (including)
Network_security_servicesMozilla3.3 (including)3.3 (including)
Network_security_servicesMozilla3.3.1 (including)3.3.1 (including)
Network_security_servicesMozilla3.3.2 (including)3.3.2 (including)
Network_security_servicesMozilla3.4 (including)3.4 (including)
Network_security_servicesMozilla3.4.1 (including)3.4.1 (including)
Network_security_servicesMozilla3.4.2 (including)3.4.2 (including)
Network_security_servicesMozilla3.5 (including)3.5 (including)
Network_security_servicesMozilla3.6 (including)3.6 (including)
Network_security_servicesMozilla3.6.1 (including)3.6.1 (including)
Network_security_servicesMozilla3.7 (including)3.7 (including)
Network_security_servicesMozilla3.7.1 (including)3.7.1 (including)
Network_security_servicesMozilla3.7.2 (including)3.7.2 (including)
Network_security_servicesMozilla3.7.3 (including)3.7.3 (including)
Network_security_servicesMozilla3.7.5 (including)3.7.5 (including)
Network_security_servicesMozilla3.7.7 (including)3.7.7 (including)
Network_security_servicesMozilla3.8 (including)3.8 (including)
Network_security_servicesMozilla3.9 (including)3.9 (including)
Network_security_servicesMozilla3.11.2 (including)3.11.2 (including)
Network_security_servicesMozilla3.11.3 (including)3.11.3 (including)
Network_security_servicesMozilla3.11.4 (including)3.11.4 (including)
Network_security_servicesMozilla3.11.5 (including)3.11.5 (including)
NssUbuntudevel*
NssUbuntuhardy*
NssUbuntulucid*
NssUbuntunatty*
NssUbuntuoneiric*
NssUbuntuprecise*

References