Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-17023

Опубликовано: 08 янв. 2020
Источник: debian
EPSS Низкий

Описание

After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects Firefox < 72.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed72.0-1package
nssfixed2:3.49-1package
nssnot-affectedstretchpackage
nssnot-affectedjessiepackage

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2020-01/#CVE-2019-17023

  • https://hg.mozilla.org/projects/nss/rev/d64102b76a437f24d98a20480dcc9f1655143e7c

  • https://hg.mozilla.org/projects/nss/rev/8a2bd40e7f89a796cf24a0ff7cfb67c6e69c5c78

EPSS

Процентиль: 75%
0.00899
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 6 лет назад

After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects Firefox < 72.

CVSS3: 5.3
redhat
около 6 лет назад

After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects Firefox < 72.

CVSS3: 6.5
nvd
около 6 лет назад

After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects Firefox < 72.

CVSS3: 6.5
github
больше 3 лет назад

After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects Firefox < 72.

CVSS3: 6.5
fstec
около 6 лет назад

Уязвимость расширения HelloRetryRequest браузера Firefox, позволяющая нарушителю оказать воздействие на целостность данных

EPSS

Процентиль: 75%
0.00899
Низкий