Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-1492

Опубликовано: 25 мар. 2014
Источник: debian
EPSS Низкий

Описание

The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nssfixed2:3.16-1package
nssfixed3.12.8-1+squeeze8squeezepackage
iceweaselnot-affectedpackage
icedovenot-affectedpackage

EPSS

Процентиль: 74%
0.00852
Низкий

Связанные уязвимости

ubuntu
больше 11 лет назад

The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

redhat
больше 11 лет назад

The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

nvd
больше 11 лет назад

The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

github
больше 3 лет назад

The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

oracle-oval
почти 11 лет назад

ELSA-2014-1073: nss, nss-util, nss-softokn security, bug fix, and enhancement update (LOW)

EPSS

Процентиль: 74%
0.00852
Низкий