Lucene search

K
prionPRIOn knowledge basePRION:CVE-2013-5606
HistoryNov 18, 2013 - 5:23 a.m.

Design/Logic Flaw

2013-11-1805:23:00
PRIOn knowledge base
www.prio-n.com
9

7 High

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

81.7%

The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate.

References