Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-3170

Опубликовано: 14 июл. 2010
Источник: redhat
CVSS2: 2.6
EPSS Низкий

Описание

Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 recognize a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=630047firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely

EPSS

Процентиль: 78%
0.01158
Низкий

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
больше 14 лет назад

Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 recognize a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

nvd
больше 14 лет назад

Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 recognize a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

debian
больше 14 лет назад

Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird bef ...

github
около 3 лет назад

Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 recognize a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

oracle-oval
больше 14 лет назад

ELSA-2010-0862: nss security update (LOW)

EPSS

Процентиль: 78%
0.01158
Низкий

2.6 Low

CVSS2