Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-5606

Опубликовано: 18 нояб. 2013
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5.8

Описание

The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate.

РелизСтатусПримечание
devel

not-affected

2:3.15.3-1
lucid

released

3.15.3-0ubuntu0.10.04.1
precise

released

3.15.3-0ubuntu0.12.04.1
quantal

released

3.15.3-0ubuntu0.12.10.1
raring

released

2:3.15.3-0ubuntu0.13.04.1
saucy

released

2:3.15.3-0ubuntu0.13.10.1
upstream

released

3.15.3

Показывать по

EPSS

Процентиль: 70%
0.00661
Низкий

5.8 Medium

CVSS2

Связанные уязвимости

redhat
почти 12 лет назад

The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate.

nvd
почти 12 лет назад

The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate.

debian
почти 12 лет назад

The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Netw ...

github
больше 3 лет назад

The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate.

oracle-oval
больше 11 лет назад

ELSA-2013-1829: nss, nspr, and nss-util security update (IMPORTANT)

EPSS

Процентиль: 70%
0.00661
Низкий

5.8 Medium

CVSS2