Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2013-4566
HistoryDec 12, 2013 - 6:55 p.m.

CVE-2013-4566

2013-12-1218:55:00
Debian Security Bug Tracker
security-tracker.debian.org
13

0.007 Low

EPSS

Percentile

80.3%

mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVerifyClient setting in the directory context, which allows remote attackers to bypass intended access restrictions.

OSVersionArchitecturePackageVersionFilename
Debian9alllibapache2-mod-nss< 1.0.14-1libapache2-mod-nss_1.0.14-1_all.deb