CVE-2013-5606
Summary
| CVE | CVE-2013-5606 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-11-18 05:23:00 UTC |
| Updated | 2018-10-09 19:34:00 UTC |
| Description | The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| MFSA 2013-103: Miscellaneous Network Security Services (NSS) vulnerabilities |
CONFIRM |
www.mozilla.org |
|
| Gentoo Security |
GENTOO |
security.gentoo.org |
|
| VMSA-2014-0012 | United States |
CONFIRM |
www.vmware.com |
|
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
|
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
|
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
|
| openSUSE-SU-2013:1732-1: moderate: update for mozilla-nss |
SUSE |
lists.opensuse.org |
|
| Debian -- Security Information -- DSA-2994-1 nss |
DEBIAN |
www.debian.org |
|
| Oracle Critical Patch Update - January 2015 |
CONFIRM |
www.oracle.com |
|
| Full Disclosure: NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities |
FULLDISC |
seclists.org |
|
| Oracle VM Server for x86 Bulletin - July 2016 |
CONFIRM |
www.oracle.com |
|
| 2016-10 Security Bulletin: CTPView: Multiple vulnerabilities in CTPView - Juniper Networks |
CONFIRM |
kb.juniper.net |
|
| USN-2030-1: NSS vulnerabilities | Ubuntu |
UBUNTU |
www.ubuntu.com |
|
| Gentoo Linux Documentation
--
Mozilla Network Security Service: Multiple vulnerabilities |
GENTOO |
security.gentoo.org |
|
| 910438 – (CVE-2013-5606) CERT_VerifyCert returns SECSuccess (saying certificate is good) even for bad certificates, when the CERTVerifyLog log parameter is given |
CONFIRM |
bugzilla.mozilla.org |
|
| NSS 3.15.3 release notes - Mozilla | MDN |
CONFIRM |
developer.mozilla.org |
|
| Mozilla Network Security Services CVE-2013-5606 Certificate Validation Security Bypass Vulnerability |
BID |
www.securityfocus.com |
|
| Oracle Critical Patch Update - October 2014 |
CONFIRM |
www.oracle.com |
|
| Oracle Critical Patch Update - July 2014 |
CONFIRM |
www.oracle.com |
|
| [security-announce] SUSE-SU-2013:1807-1: important: Security update for |
SUSE |
lists.opensuse.org |
|
| SecurityFocus |
BUGTRAQ |
www.securityfocus.com |
|
| Oracle Critical Patch Update - January 2016 |
CONFIRM |
www.oracle.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 390279 Oracle Managed Virtualization (VM) Server for x86 Security Update for nss (OVMSA-2023-0014)