CVE Vulnerabilities

CVE-2019-11727

Improper Certificate Validation

Published: Jul 23, 2019 | Modified: Jul 30, 2019
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
3.4 LOW
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
Ubuntu
MEDIUM

A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those are the only ones advertised by server in CertificateRequest in TLS 1.3. PKCS#1 v1.5 signatures should not be used for TLS 1.3 messages. This vulnerability affects Firefox < 68.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla * 68.0 (excluding)
Red Hat Enterprise Linux 7 RedHat nspr-0:4.25.0-2.el7_9 *
Red Hat Enterprise Linux 7 RedHat nss-0:3.53.1-3.el7_9 *
Red Hat Enterprise Linux 7 RedHat nss-softokn-0:3.53.1-6.el7_9 *
Red Hat Enterprise Linux 7 RedHat nss-util-0:3.53.1-1.el7_9 *
Red Hat Enterprise Linux 8 RedHat nspr-0:4.21.0-2.el8_0 *
Red Hat Enterprise Linux 8 RedHat nss-0:3.44.0-7.el8_0 *
Red Hat OpenShift Do RedHat openshiftdo/odo-init-image-rhel7:1.1.3-2 *
Firefox Ubuntu bionic *
Firefox Ubuntu cosmic *
Firefox Ubuntu devel *
Firefox Ubuntu disco *
Firefox Ubuntu eoan *
Firefox Ubuntu focal *
Firefox Ubuntu groovy *
Firefox Ubuntu hirsute *
Firefox Ubuntu impish *
Firefox Ubuntu jammy *
Firefox Ubuntu kinetic *
Firefox Ubuntu lunar *
Firefox Ubuntu mantic *
Firefox Ubuntu noble *
Firefox Ubuntu trusty *
Firefox Ubuntu upstream *
Firefox Ubuntu xenial *
Mozjs38 Ubuntu bionic *
Mozjs38 Ubuntu esm-apps/bionic *
Mozjs38 Ubuntu upstream *
Mozjs52 Ubuntu bionic *
Mozjs52 Ubuntu cosmic *
Mozjs52 Ubuntu disco *
Mozjs52 Ubuntu eoan *
Mozjs52 Ubuntu esm-apps/focal *
Mozjs52 Ubuntu esm-infra/bionic *
Mozjs52 Ubuntu focal *
Mozjs52 Ubuntu groovy *
Mozjs52 Ubuntu upstream *
Mozjs60 Ubuntu cosmic *
Mozjs60 Ubuntu disco *
Mozjs60 Ubuntu eoan *
Mozjs60 Ubuntu upstream *
Nss Ubuntu cosmic *
Nss Ubuntu devel *
Nss Ubuntu disco *
Nss Ubuntu eoan *
Nss Ubuntu focal *
Nss Ubuntu groovy *
Nss Ubuntu hirsute *
Nss Ubuntu impish *
Nss Ubuntu jammy *
Nss Ubuntu kinetic *
Nss Ubuntu lunar *
Nss Ubuntu mantic *
Nss Ubuntu noble *
Nss Ubuntu trusty *
Nss Ubuntu upstream *
Thunderbird Ubuntu cosmic *
Thunderbird Ubuntu disco *
Thunderbird Ubuntu upstream *
Thunderbird Ubuntu xenial *

Potential Mitigations

References