Lucene search

K
cvelistMozillaCVELIST:CVE-2013-5606
HistoryNov 16, 2013 - 3:00 p.m.

CVE-2013-5606

2013-11-1615:00:00
mozilla
www.cve.org
2

5.2 Medium

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

81.7%

The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate.

References