CVE Vulnerabilities

CVE-2011-5094

Published: Jun 16, 2012 | Modified: May 17, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW

Mozilla Network Security Services (NSS) 3.x, with certain settings of the SSL_ENABLE_RENEGOTIATION option, does not properly restrict client-initiated renegotiation within the SSL and TLS protocols, which might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection, a different vulnerability than CVE-2011-1473. NOTE: it can also be argued that it is the responsibility of server deployments, not a security library, to prevent or limit renegotiation when it is inappropriate within a specific environment

Affected Software

Name Vendor Start Version End Version
Network_security_services Mozilla 3.2 (including) 3.2 (including)
Network_security_services Mozilla 3.2.1 (including) 3.2.1 (including)
Network_security_services Mozilla 3.3 (including) 3.3 (including)
Network_security_services Mozilla 3.3.1 (including) 3.3.1 (including)
Network_security_services Mozilla 3.3.2 (including) 3.3.2 (including)
Network_security_services Mozilla 3.4 (including) 3.4 (including)
Network_security_services Mozilla 3.4.1 (including) 3.4.1 (including)
Network_security_services Mozilla 3.4.2 (including) 3.4.2 (including)
Network_security_services Mozilla 3.5 (including) 3.5 (including)
Network_security_services Mozilla 3.6 (including) 3.6 (including)
Network_security_services Mozilla 3.6.1 (including) 3.6.1 (including)
Network_security_services Mozilla 3.7 (including) 3.7 (including)
Network_security_services Mozilla 3.7.1 (including) 3.7.1 (including)
Network_security_services Mozilla 3.7.2 (including) 3.7.2 (including)
Network_security_services Mozilla 3.7.3 (including) 3.7.3 (including)
Network_security_services Mozilla 3.7.5 (including) 3.7.5 (including)
Network_security_services Mozilla 3.7.7 (including) 3.7.7 (including)
Network_security_services Mozilla 3.8 (including) 3.8 (including)
Network_security_services Mozilla 3.9 (including) 3.9 (including)
Network_security_services Mozilla 3.11.2 (including) 3.11.2 (including)
Network_security_services Mozilla 3.11.3 (including) 3.11.3 (including)
Network_security_services Mozilla 3.11.4 (including) 3.11.4 (including)
Network_security_services Mozilla 3.11.5 (including) 3.11.5 (including)
Nss Ubuntu devel *
Nss Ubuntu hardy *
Nss Ubuntu lucid *
Nss Ubuntu natty *
Nss Ubuntu oneiric *
Nss Ubuntu precise *

References