2014-01-18 23:55:03 2018-10-09 21:33:58

The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certificate during certain handshake traffic.

Vector

NETWORK

Complexity

MEDIUM

Authentication

NONE

Confidentiality

PARTIAL

Integrity

PARTIAL

Availability

NONE
Mozilla Network Security Services 3.15.2 Mozilla Network Security Services 3.15.3 Mozilla Network Security Services 3.15.1 Mozilla Network Security Services 3.15 Mozilla Network Security Services 3.14.5 Mozilla Network Security Services 3.14.2 Mozilla Network Security Services 3.14.4 Mozilla Network Security Services 3.14.3 Mozilla Network Security Services 3.14.1 Mozilla Network Security Services 3.14 Mozilla Network Security Services 3.12.11 Mozilla Network Security Services 3.12.10 Mozilla Network Security Services 3.12.9 Mozilla Network Security Services 3.12.6 Mozilla Network Security Services 3.12.8 Mozilla Network Security Services 3.12.7 Mozilla Network Security Services 3.12.5 Mozilla Network Security Services 3.12.4 Mozilla Network Security Services 3.12.3.1 Mozilla Network Security Services 3.12.3.2 Mozilla Network Security Services 3.12.1 Mozilla Network Security Services 3.12.2 Mozilla Network Security Services 3.12.3 Mozilla Network Security Services 3.12 Mozilla Network Security Services 3.11.5 Mozilla Network Security Services 3.11.2 Mozilla Network Security Services 3.11.3 Mozilla Network Security Services 3.11.4 Mozilla Network Security Services 3.9 Mozilla Network Security Services 3.8 Mozilla Network Security Services 3.7.7 Mozilla Network Security Services 3.7.5 Mozilla Network Security Services 3.7.3 Mozilla Network Security Services 3.7.2 Mozilla Network Security Services 3.7.1 Mozilla Network Security Services 3.7 Mozilla Network Security Services 3.6.1 Mozilla Network Security Services 3.6 Mozilla Network Security Services 3.5 Mozilla Network Security Services 3.4.2 Mozilla Network Security Services 3.4.1 Mozilla Network Security Services 3.4 Mozilla Network Security Services 3.3.2 Mozilla Network Security Services 3.3.1 Mozilla Network Security Services 3.3 Mozilla Network Security Services 3.2.1 Mozilla Network Security Services 3.2