CVE Vulnerabilities

CVE-2013-1740

Published: Jan 18, 2014 | Modified: Oct 09, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certificate during certain handshake traffic.

Affected Software

Name Vendor Start Version End Version
Network_security_services Mozilla 3.11.2 3.11.2
Network_security_services Mozilla 3.6.1 3.6.1
Network_security_services Mozilla 3.12.5 3.12.5
Network_security_services Mozilla 3.2 3.2
Network_security_services Mozilla 3.15 3.15
Network_security_services Mozilla 3.11.4 3.11.4
Network_security_services Mozilla 3.7.7 3.7.7
Network_security_services Mozilla 3.14.1 3.14.1
Network_security_services Mozilla 3.7.5 3.7.5
Network_security_services Mozilla 3.7.1 3.7.1
Network_security_services Mozilla 3.12.9 3.12.9
Network_security_services Mozilla 3.12.3.1 3.12.3.1
Network_security_services Mozilla 3.6 3.6
Network_security_services Mozilla 3.12.6 3.12.6
Network_security_services Mozilla 3.2.1 3.2.1
Network_security_services Mozilla 3.12.8 3.12.8
Network_security_services Mozilla 3.15.1 3.15.1
Network_security_services Mozilla 3.12.11 3.12.11
Network_security_services Mozilla 3.14.3 3.14.3
Network_security_services Mozilla 3.14.4 3.14.4
Network_security_services Mozilla 3.9 3.9
Network_security_services Mozilla 3.4 3.4
Network_security_services Mozilla 3.14 3.14
Network_security_services Mozilla 3.8 3.8
Network_security_services Mozilla 3.4.1 3.4.1
Network_security_services Mozilla 3.11.5 3.11.5
Network_security_services Mozilla 3.7 3.7
Network_security_services Mozilla 3.12.2 3.12.2
Network_security_services Mozilla 3.7.2 3.7.2
Network_security_services Mozilla 3.12.10 3.12.10
Network_security_services Mozilla 3.3 3.3
Network_security_services Mozilla 3.12.4 3.12.4
Network_security_services Mozilla 3.12.1 3.12.1
Network_security_services Mozilla 3.12.3.2 3.12.3.2
Network_security_services Mozilla 3.7.3 3.7.3
Network_security_services Mozilla 3.15.2 3.15.2
Network_security_services Mozilla 3.4.2 3.4.2
Network_security_services Mozilla 3.12.3 3.12.3
Network_security_services Mozilla 3.3.2 3.3.2
Network_security_services Mozilla 3.14.5 3.14.5
Network_security_services Mozilla 3.5 3.5
Network_security_services Mozilla 3.14.2 3.14.2
Network_security_services Mozilla 3.12.7 3.12.7
Network_security_services Mozilla 3.11.3 3.11.3
Network_security_services Mozilla * 3.15.3
Network_security_services Mozilla 3.12 3.12
Network_security_services Mozilla 3.3.1 3.3.1

References