Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23695
HistoryApr 10, 2020 - 12:33 a.m.

Spoofing Attack

2020-04-1000:33:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16

0.014 Low

EPSS

Percentile

86.3%

nspr is vulnerable to spoofing attacks. Dan Kaminsky found that browsers still accept certificates with MD2 hash signatures, even though MD2 is no longer considered a cryptographically strong algorithm. This could make it easier for an attacker to create a malicious certificate that would be treated as trusted by a browser. NSS now disables the use of MD2 and MD4 algorithms inside signatures by default.

References