Description
The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certificate during certain handshake traffic.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2013-1767 | The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certificate during certain handshake traffic. |
Ubuntu USN |
USN-2088-1 | NSS vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-08-06T15:13:32.451Z
Reserved: 2013-02-13T00:00:00.000Z
Link: CVE-2013-1740
No data.
Status : Modified
Published: 2014-01-18T22:55:03.117
Modified: 2026-04-29T01:13:23.040
Link: CVE-2013-1740
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN