Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:15720
HistoryMay 02, 2019 - 5:03 a.m.

Man-in-the-Middle Attack

2019-05-0205:03:48
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16

0.002 Low

EPSS

Percentile

53.1%

nss-util is vulnerable to a man-in-the-middle attack. The library accepts a wildcard character that is embedded in an internationalized domain name’s U-labels in the cert_TestHostName function in lib/certdb/certdb.c , allowing a malicious user to spoof SSL servers via a crafted certificate.

References