Уязвимость обхода криптографических механизмов защиты в Mozilla Network Security Services через недостаточные ограничения в обмене ключами Диффи-Хеллмана
Описание
Mozilla Network Security Services (NSS) до версии 3.15.4, используемая в Mozilla Firefox до версии 27.0, Firefox ESR 24.x до версии 24.3, Thunderbird до версии 24.3, SeaMonkey до версии 2.24 и других продуктах, некорректно ограничивает публичные значения в обмене ключами Диффи-Хеллмана. Это упрощает злоумышленникам обход криптографических механизмов защиты в обработке тикетов через использование определенного значения.
Затронутые версии ПО
- Mozilla Network Security Services (NSS) до 3.15.4
- Mozilla Firefox до 27.0
- Mozilla Firefox ESR 24.x до 24.3
- Mozilla Thunderbird до 24.3
- Mozilla SeaMonkey до 2.24
Тип уязвимости
Обход криптографических механизмов защиты
Ссылки
- PatchVendor Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Not Applicable
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVendor Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Одно из
Одно из
Одно из
Одно из
Одно из
Одно из
EPSS
4.3 Medium
CVSS2
Дефекты
Связанные уязвимости
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanisms in ticket handling by leveraging use of a certain value.
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanisms in ticket handling by leveraging use of a certain value.
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozi ...
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanisms in ticket handling by leveraging use of a certain value.
ELSA-2014-1246: nss and nspr security, bug fix, and enhancement update (MODERATE)
EPSS
4.3 Medium
CVSS2