Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fxvw-6w4h-3mx5

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

Ссылки

EPSS

Процентиль: 74%
0.00852
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 11 лет назад

The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

redhat
больше 11 лет назад

The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

nvd
больше 11 лет назад

The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

debian
больше 11 лет назад

The cert_TestHostName function in lib/certdb/certdb.c in the certifica ...

oracle-oval
почти 11 лет назад

ELSA-2014-1073: nss, nss-util, nss-softokn security, bug fix, and enhancement update (LOW)

EPSS

Процентиль: 74%
0.00852
Низкий

Дефекты

CWE-20