The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly set the minimum key length for Diffie-Hellman Ephemeral (DHE) mode, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2123-1 | New NSS packages fix cryptographic weaknesses |
EUVD |
EUVD-2010-3173 | The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly set the minimum key length for Diffie-Hellman Ephemeral (DHE) mode, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack. |
Ubuntu USN |
USN-1007-1 | NSS vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T03:03:18.679Z
Reserved: 2010-08-27T00:00:00
Link: CVE-2010-3173
No data.
Status : Deferred
Published: 2010-10-21T19:00:02.583
Modified: 2025-04-11T00:51:21.963
Link: CVE-2010-3173
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN