nss before version 3.30 is vulnerable to a remote denial of service during the session handshake when using SessionTicket extension and ECDHE-ECDSA.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Network_security_services | Mozilla | * | 3.30 (excluding) |
Nss | Ubuntu | vivid/stable-phone-overlay | * |
Such a scenario is commonly observed when: