The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certificate during certain handshake traffic.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:50
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.html - | |
References | () http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.html - | |
References | () http://seclists.org/fulldisclosure/2014/Dec/23 - | |
References | () http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html - | |
References | () http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html - | |
References | () http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html - | |
References | () http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html - | |
References | () http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html - | |
References | () http://www.securityfocus.com/archive/1/534161/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/64944 - | |
References | () http://www.ubuntu.com/usn/USN-2088-1 - | |
References | () http://www.vmware.com/security/advisories/VMSA-2014-0012.html - | |
References | () https://bugs.gentoo.org/show_bug.cgi?id=498172 - | |
References | () https://bugzilla.mozilla.org/show_bug.cgi?id=919877 - Exploit | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=1053725 - | |
References | () https://developer.mozilla.org/docs/NSS/NSS_3.15.4_release_notes - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/90394 - |
Information
Published : 2014-01-18 22:55
Updated : 2024-11-21 01:50
NVD link : CVE-2013-1740
Mitre link : CVE-2013-1740
CVE.ORG link : CVE-2013-1740
JSON object : View
Products Affected
mozilla
- network_security_services
CWE
CWE-310
Cryptographic Issues