Описание
The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 7 | nss | Not affected | ||
Red Hat Enterprise Linux 5 | nspr | Fixed | RHSA-2013:1791 | 05.12.2013 |
Red Hat Enterprise Linux 5 | nss | Fixed | RHSA-2013:1791 | 05.12.2013 |
Red Hat Enterprise Linux 6 | nspr | Fixed | RHSA-2013:1829 | 12.12.2013 |
Red Hat Enterprise Linux 6 | nss | Fixed | RHSA-2013:1829 | 12.12.2013 |
Red Hat Enterprise Linux 6 | nss-util | Fixed | RHSA-2013:1829 | 12.12.2013 |
RHEV 3.X Hypervisor and Agents for RHEL-6 | rhev-hypervisor6 | Fixed | RHSA-2014:0041 | 21.01.2014 |
Показывать по
Дополнительная информация
Статус:
4.3 Medium
CVSS2
Связанные уязвимости
The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate.
The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate.
The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Netw ...
The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate.
ELSA-2013-1829: nss, nspr, and nss-util security update (IMPORTANT)
4.3 Medium
CVSS2