CVE Vulnerabilities

CVE-2019-11727

Improper Certificate Validation

Published: Jul 23, 2019 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
3.4 LOW
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those are the only ones advertised by server in CertificateRequest in TLS 1.3. PKCS#1 v1.5 signatures should not be used for TLS 1.3 messages. This vulnerability affects Firefox < 68.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla*68.0 (excluding)
Red Hat Enterprise Linux 7RedHatnspr-0:4.25.0-2.el7_9*
Red Hat Enterprise Linux 7RedHatnss-0:3.53.1-3.el7_9*
Red Hat Enterprise Linux 7RedHatnss-softokn-0:3.53.1-6.el7_9*
Red Hat Enterprise Linux 7RedHatnss-util-0:3.53.1-1.el7_9*
Red Hat Enterprise Linux 8RedHatnspr-0:4.21.0-2.el8_0*
Red Hat Enterprise Linux 8RedHatnss-0:3.44.0-7.el8_0*
Red Hat OpenShift DoRedHatopenshiftdo/odo-init-image-rhel7:1.1.3-2*
FirefoxUbuntubionic*
FirefoxUbuntucosmic*
FirefoxUbuntudevel*
FirefoxUbuntudisco*
FirefoxUbuntueoan*
FirefoxUbuntufocal*
FirefoxUbuntugroovy*
FirefoxUbuntuhirsute*
FirefoxUbuntuimpish*
FirefoxUbuntujammy*
FirefoxUbuntukinetic*
FirefoxUbuntulunar*
FirefoxUbuntumantic*
FirefoxUbuntunoble*
FirefoxUbuntutrusty*
FirefoxUbuntuupstream*
FirefoxUbuntuxenial*
Mozjs38Ubuntubionic*
Mozjs38Ubuntuesm-apps/bionic*
Mozjs38Ubuntuupstream*
Mozjs52Ubuntubionic*
Mozjs52Ubuntucosmic*
Mozjs52Ubuntudisco*
Mozjs52Ubuntueoan*
Mozjs52Ubuntuesm-apps/focal*
Mozjs52Ubuntuesm-infra/bionic*
Mozjs52Ubuntufocal*
Mozjs52Ubuntugroovy*
Mozjs52Ubuntuupstream*
Mozjs60Ubuntucosmic*
Mozjs60Ubuntudisco*
Mozjs60Ubuntueoan*
Mozjs60Ubuntuupstream*
NssUbuntucosmic*
NssUbuntudevel*
NssUbuntudisco*
NssUbuntueoan*
NssUbuntuesm-infra/focal*
NssUbuntufocal*
NssUbuntugroovy*
NssUbuntuhirsute*
NssUbuntuimpish*
NssUbuntujammy*
NssUbuntukinetic*
NssUbuntulunar*
NssUbuntumantic*
NssUbuntunoble*
NssUbuntutrusty*
NssUbuntuupstream*
ThunderbirdUbuntucosmic*
ThunderbirdUbuntudisco*
ThunderbirdUbuntuupstream*
ThunderbirdUbuntuxenial*

Potential Mitigations

References