Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-1740

Опубликовано: 18 янв. 2014
Источник: ubuntu
Приоритет: medium
CVSS2: 5.8

Описание

The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certificate during certain handshake traffic.

РелизСтатусПримечание
devel

released

2:3.15.4-1ubuntu3
lucid

released

3.15.4-0ubuntu0.10.04.1
precise

released

3.15.4-0ubuntu0.12.04.1
quantal

released

3.15.4-0ubuntu0.12.10.1
raring

ignored

end of life
saucy

released

2:3.15.4-0ubuntu0.13.10.1
upstream

released

2:3.15.4-1

Показывать по

5.8 Medium

CVSS2

Связанные уязвимости

redhat
больше 11 лет назад

The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certificate during certain handshake traffic.

nvd
больше 11 лет назад

The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certificate during certain handshake traffic.

debian
больше 11 лет назад

The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Net ...

github
больше 3 лет назад

The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certificate during certain handshake traffic.

oracle-oval
почти 11 лет назад

ELSA-2014-1246: nss and nspr security, bug fix, and enhancement update (MODERATE)

5.8 Medium

CVSS2