CVE Vulnerabilities

CVE-2013-6628

Published: Nov 13, 2013 | Modified: Sep 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

net/socket/ssl_client_socket_nss.cc in the TLS implementation in Google Chrome before 31.0.1650.48 does not ensure that a servers X.509 certificate is the same during renegotiation as it was before renegotiation, which might allow remote web servers to interfere with trust relationships by renegotiating a session.

Affected Software

Name Vendor Start Version End Version
Chrome Google * 31.0.1650.47 (including)
Chrome Google 31.0.1650.0 (including) 31.0.1650.0 (including)
Chrome Google 31.0.1650.2 (including) 31.0.1650.2 (including)
Chrome Google 31.0.1650.3 (including) 31.0.1650.3 (including)
Chrome Google 31.0.1650.4 (including) 31.0.1650.4 (including)
Chrome Google 31.0.1650.5 (including) 31.0.1650.5 (including)
Chrome Google 31.0.1650.6 (including) 31.0.1650.6 (including)
Chrome Google 31.0.1650.7 (including) 31.0.1650.7 (including)
Chrome Google 31.0.1650.8 (including) 31.0.1650.8 (including)
Chrome Google 31.0.1650.9 (including) 31.0.1650.9 (including)
Chrome Google 31.0.1650.10 (including) 31.0.1650.10 (including)
Chrome Google 31.0.1650.11 (including) 31.0.1650.11 (including)
Chrome Google 31.0.1650.12 (including) 31.0.1650.12 (including)
Chrome Google 31.0.1650.13 (including) 31.0.1650.13 (including)
Chrome Google 31.0.1650.14 (including) 31.0.1650.14 (including)
Chrome Google 31.0.1650.15 (including) 31.0.1650.15 (including)
Chrome Google 31.0.1650.16 (including) 31.0.1650.16 (including)
Chrome Google 31.0.1650.17 (including) 31.0.1650.17 (including)
Chrome Google 31.0.1650.18 (including) 31.0.1650.18 (including)
Chrome Google 31.0.1650.19 (including) 31.0.1650.19 (including)
Chrome Google 31.0.1650.20 (including) 31.0.1650.20 (including)
Chrome Google 31.0.1650.22 (including) 31.0.1650.22 (including)
Chrome Google 31.0.1650.23 (including) 31.0.1650.23 (including)
Chrome Google 31.0.1650.25 (including) 31.0.1650.25 (including)
Chrome Google 31.0.1650.26 (including) 31.0.1650.26 (including)
Chrome Google 31.0.1650.27 (including) 31.0.1650.27 (including)
Chrome Google 31.0.1650.28 (including) 31.0.1650.28 (including)
Chrome Google 31.0.1650.29 (including) 31.0.1650.29 (including)
Chrome Google 31.0.1650.30 (including) 31.0.1650.30 (including)
Chrome Google 31.0.1650.31 (including) 31.0.1650.31 (including)
Chrome Google 31.0.1650.32 (including) 31.0.1650.32 (including)
Chrome Google 31.0.1650.33 (including) 31.0.1650.33 (including)
Chrome Google 31.0.1650.34 (including) 31.0.1650.34 (including)
Chrome Google 31.0.1650.35 (including) 31.0.1650.35 (including)
Chrome Google 31.0.1650.36 (including) 31.0.1650.36 (including)
Chrome Google 31.0.1650.37 (including) 31.0.1650.37 (including)
Chrome Google 31.0.1650.38 (including) 31.0.1650.38 (including)
Chrome Google 31.0.1650.39 (including) 31.0.1650.39 (including)
Chrome Google 31.0.1650.41 (including) 31.0.1650.41 (including)
Chrome Google 31.0.1650.42 (including) 31.0.1650.42 (including)
Chrome Google 31.0.1650.43 (including) 31.0.1650.43 (including)
Chrome Google 31.0.1650.44 (including) 31.0.1650.44 (including)
Chrome Google 31.0.1650.45 (including) 31.0.1650.45 (including)
Chrome Google 31.0.1650.46 (including) 31.0.1650.46 (including)

References