Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-1492

Опубликовано: 18 мар. 2014
Источник: redhat
CVSS2: 2.6

Описание

The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

It was found that the implementation of Internationalizing Domain Names in Applications (IDNA) hostname matching in NSS did not follow the RFC 6125 recommendations. This could lead to certain invalid certificates with international characters to be accepted as valid.

Дополнительная информация

Статус:

Low
Дефект:
CWE-172->CWE-697->CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=1079851nss: IDNA hostname matching code does not follow RFC 6125 recommendation (MFSA 2014-45)

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

nvd
больше 11 лет назад

The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

debian
больше 11 лет назад

The cert_TestHostName function in lib/certdb/certdb.c in the certifica ...

github
больше 3 лет назад

The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

oracle-oval
почти 11 лет назад

ELSA-2014-1073: nss, nss-util, nss-softokn security, bug fix, and enhancement update (LOW)

2.6 Low

CVSS2