CVE Vulnerabilities

CVE-2013-1740

Published: Jan 18, 2014 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certificate during certain handshake traffic.

Affected Software

NameVendorStart VersionEnd Version
Network_security_servicesMozilla*3.15.3 (including)
Network_security_servicesMozilla3.2 (including)3.2 (including)
Network_security_servicesMozilla3.2.1 (including)3.2.1 (including)
Network_security_servicesMozilla3.3 (including)3.3 (including)
Network_security_servicesMozilla3.3.1 (including)3.3.1 (including)
Network_security_servicesMozilla3.3.2 (including)3.3.2 (including)
Network_security_servicesMozilla3.4 (including)3.4 (including)
Network_security_servicesMozilla3.4.1 (including)3.4.1 (including)
Network_security_servicesMozilla3.4.2 (including)3.4.2 (including)
Network_security_servicesMozilla3.5 (including)3.5 (including)
Network_security_servicesMozilla3.6 (including)3.6 (including)
Network_security_servicesMozilla3.6.1 (including)3.6.1 (including)
Network_security_servicesMozilla3.7 (including)3.7 (including)
Network_security_servicesMozilla3.7.1 (including)3.7.1 (including)
Network_security_servicesMozilla3.7.2 (including)3.7.2 (including)
Network_security_servicesMozilla3.7.3 (including)3.7.3 (including)
Network_security_servicesMozilla3.7.5 (including)3.7.5 (including)
Network_security_servicesMozilla3.7.7 (including)3.7.7 (including)
Network_security_servicesMozilla3.8 (including)3.8 (including)
Network_security_servicesMozilla3.9 (including)3.9 (including)
Network_security_servicesMozilla3.11.2 (including)3.11.2 (including)
Network_security_servicesMozilla3.11.3 (including)3.11.3 (including)
Network_security_servicesMozilla3.11.4 (including)3.11.4 (including)
Network_security_servicesMozilla3.11.5 (including)3.11.5 (including)
Network_security_servicesMozilla3.12 (including)3.12 (including)
Network_security_servicesMozilla3.12.1 (including)3.12.1 (including)
Network_security_servicesMozilla3.12.2 (including)3.12.2 (including)
Network_security_servicesMozilla3.12.3 (including)3.12.3 (including)
Network_security_servicesMozilla3.12.3.1 (including)3.12.3.1 (including)
Network_security_servicesMozilla3.12.3.2 (including)3.12.3.2 (including)
Network_security_servicesMozilla3.12.4 (including)3.12.4 (including)
Network_security_servicesMozilla3.12.5 (including)3.12.5 (including)
Network_security_servicesMozilla3.12.6 (including)3.12.6 (including)
Network_security_servicesMozilla3.12.7 (including)3.12.7 (including)
Network_security_servicesMozilla3.12.8 (including)3.12.8 (including)
Network_security_servicesMozilla3.12.9 (including)3.12.9 (including)
Network_security_servicesMozilla3.12.10 (including)3.12.10 (including)
Network_security_servicesMozilla3.12.11 (including)3.12.11 (including)
Network_security_servicesMozilla3.14 (including)3.14 (including)
Network_security_servicesMozilla3.14.1 (including)3.14.1 (including)
Network_security_servicesMozilla3.14.2 (including)3.14.2 (including)
Network_security_servicesMozilla3.14.3 (including)3.14.3 (including)
Network_security_servicesMozilla3.14.4 (including)3.14.4 (including)
Network_security_servicesMozilla3.14.5 (including)3.14.5 (including)
Network_security_servicesMozilla3.15 (including)3.15 (including)
Network_security_servicesMozilla3.15.1 (including)3.15.1 (including)
Network_security_servicesMozilla3.15.2 (including)3.15.2 (including)
Red Hat Enterprise Linux 5RedHatnss-0:3.16.1-2.el5*
Red Hat Enterprise Linux 6RedHatnspr-0:4.10.6-1.el6_5*
Red Hat Enterprise Linux 6RedHatnss-0:3.16.1-4.el6_5*
Red Hat Enterprise Linux 6RedHatnss-util-0:3.16.1-1.el6_5*
NssUbuntudevel*
NssUbuntulucid*
NssUbuntuprecise*
NssUbuntuquantal*
NssUbunturaring*
NssUbuntusaucy*
NssUbuntuupstream*

References