Lucene search

K
cve[email protected]CVE-2013-5606
HistoryNov 18, 2013 - 5:23 a.m.

CVE-2013-5606

2013-11-1805:23:57
CWE-264
web.nvd.nist.gov
67
cve-2013-5606
cert_verifycert
lib/certhigh/certvfy.c
mozilla network security services
nss 3.15
remote attackers
crafted certificate

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

5.3 Medium

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

81.7%

The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate.

Affected configurations

NVD
Node
mozillanetwork_security_servicesMatch3.15
OR
mozillanetwork_security_servicesMatch3.15.1
OR
mozillanetwork_security_servicesMatch3.15.2

References

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

5.3 Medium

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

81.7%