CVE-2013-1740

The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certificate during certain handshake traffic.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
Affected Products (NVD)
VendorProductVersion
mozillanetwork_security_services
𝑥
≤ 3.15.3
mozillanetwork_security_services
3.2
mozillanetwork_security_services
3.2.1
mozillanetwork_security_services
3.3
mozillanetwork_security_services
3.3.1
mozillanetwork_security_services
3.3.2
mozillanetwork_security_services
3.4
mozillanetwork_security_services
3.4.1
mozillanetwork_security_services
3.4.2
mozillanetwork_security_services
3.5
mozillanetwork_security_services
3.6
mozillanetwork_security_services
3.6.1
mozillanetwork_security_services
3.7
mozillanetwork_security_services
3.7.1
mozillanetwork_security_services
3.7.2
mozillanetwork_security_services
3.7.3
mozillanetwork_security_services
3.7.5
mozillanetwork_security_services
3.7.7
mozillanetwork_security_services
3.8
mozillanetwork_security_services
3.9
mozillanetwork_security_services
3.11.2
mozillanetwork_security_services
3.11.3
mozillanetwork_security_services
3.11.4
mozillanetwork_security_services
3.11.5
mozillanetwork_security_services
3.12
mozillanetwork_security_services
3.12.1
mozillanetwork_security_services
3.12.2
mozillanetwork_security_services
3.12.3
mozillanetwork_security_services
3.12.3.1
mozillanetwork_security_services
3.12.3.2
mozillanetwork_security_services
3.12.4
mozillanetwork_security_services
3.12.5
mozillanetwork_security_services
3.12.6
mozillanetwork_security_services
3.12.7
mozillanetwork_security_services
3.12.8
mozillanetwork_security_services
3.12.9
mozillanetwork_security_services
3.12.10
mozillanetwork_security_services
3.12.11
mozillanetwork_security_services
3.14
mozillanetwork_security_services
3.14.1
mozillanetwork_security_services
3.14.2
mozillanetwork_security_services
3.14.3
mozillanetwork_security_services
3.14.4
mozillanetwork_security_services
3.14.5
mozillanetwork_security_services
3.15
mozillanetwork_security_services
3.15.1
mozillanetwork_security_services
3.15.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
nss
bookworm
2:3.87.1-1
fixed
bullseye
2:3.61-1+deb11u3
fixed
bullseye (security)
2:3.61-1+deb11u4
fixed
sid
2:3.105-2
fixed
squeeze
no-dsa
trixie
2:3.105-2
fixed
wheezy
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
nss
lucid
Fixed 3.15.4-0ubuntu0.10.04.1
released
precise
Fixed 3.15.4-0ubuntu0.12.04.1
released
quantal
Fixed 3.15.4-0ubuntu0.12.10.1
released
raring
ignored
saucy
Fixed 2:3.15.4-0ubuntu0.13.10.1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libfreebl3
suse enterprise desktop 15
3.36.1-1.7
fixed
suse enterprise desktop 15 SP1
3.41.1-3.13.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise sap 15
3.36.1-1.7
fixed
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
suse enterprise server 15
3.36.1-1.7
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
libfreebl3-32bit
suse enterprise desktop 15
3.36.1-1.7
fixed
suse enterprise desktop 15 SP1
3.41.1-3.13.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise sap 15
3.36.1-1.7
fixed
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
suse enterprise server 15
3.36.1-1.7
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
libfreebl3-hmac
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
libfreebl3-hmac-32bit
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
libsoftokn3
suse enterprise desktop 15
3.36.1-1.7
fixed
suse enterprise desktop 15 SP1
3.41.1-3.13.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise sap 15
3.36.1-1.7
fixed
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
suse enterprise server 15
3.36.1-1.7
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
libsoftokn3-32bit
suse enterprise desktop 15
3.36.1-1.7
fixed
suse enterprise desktop 15 SP1
3.41.1-3.13.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise sap 15
3.36.1-1.7
fixed
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
suse enterprise server 15
3.36.1-1.7
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
libsoftokn3-hmac
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
libsoftokn3-hmac-32bit
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
mozilla-nss
suse enterprise desktop 15
3.36.1-1.7
fixed
suse enterprise desktop 15 SP1
3.41.1-3.13.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise sap 15
3.36.1-1.7
fixed
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
suse enterprise server 15
3.36.1-1.7
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
mozilla-nss-32bit
suse enterprise desktop 15
3.36.1-1.7
fixed
suse enterprise desktop 15 SP1
3.41.1-3.13.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise sap 15
3.36.1-1.7
fixed
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
suse enterprise server 15
3.36.1-1.7
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
mozilla-nss-certs
suse enterprise desktop 15
3.36.1-1.7
fixed
suse enterprise desktop 15 SP1
3.41.1-3.13.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise sap 15
3.36.1-1.7
fixed
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
suse enterprise server 15
3.36.1-1.7
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
mozilla-nss-certs-32bit
suse enterprise desktop 15
3.36.1-1.7
fixed
suse enterprise desktop 15 SP1
3.41.1-3.13.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise sap 15
3.36.1-1.7
fixed
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
suse enterprise server 15
3.36.1-1.7
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
mozilla-nss-devel
suse enterprise desktop 15
3.36.1-1.7
fixed
suse enterprise desktop 15 SP1
3.41.1-3.13.1
fixed
suse enterprise sap 15
3.36.1-1.7
fixed
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 15
3.36.1-1.7
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
mozilla-nss-sysinit
suse enterprise desktop 15
3.36.1-1.7
fixed
suse enterprise desktop 15 SP1
3.41.1-3.13.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise sap 15
3.36.1-1.7
fixed
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
suse enterprise server 15
3.36.1-1.7
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
mozilla-nss-sysinit-32bit
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
mozilla-nss-tools
suse enterprise desktop 15
3.36.1-1.7
fixed
suse enterprise desktop 15 SP1
3.41.1-3.13.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise sap 15
3.36.1-1.7
fixed
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
suse enterprise server 15
3.36.1-1.7
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
nspr
RHEL 6
0:4.10.6-1.el6_5
fixed
nspr-devel
RHEL 6
0:4.10.6-1.el6_5
fixed
nss
RHEL 6
0:3.16.1-4.el6_5
fixed
nss-devel
RHEL 6
0:3.16.1-4.el6_5
fixed
nss-pkcs11-devel
RHEL 6
0:3.16.1-4.el6_5
fixed
nss-sysinit
RHEL 6
0:3.16.1-4.el6_5
fixed
nss-tools
RHEL 6
0:3.16.1-4.el6_5
fixed
nss-util
RHEL 6
0:3.16.1-1.el6_5
fixed
nss-util-devel
RHEL 6
0:3.16.1-1.el6_5
fixed
Common Weakness Enumeration
References