CVE-2013-5606

The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
mozillaCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
VendorProductVersion
mozillanetwork_security_services
3.15
mozillanetwork_security_services
3.15.1
mozillanetwork_security_services
3.15.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
nss
bullseye
2:3.61-1+deb11u3
fixed
bullseye (security)
2:3.61-1+deb11u4
fixed
bookworm
2:3.87.1-1
fixed
sid
2:3.105-2
fixed
trixie
2:3.105-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
nss
saucy
Fixed 2:3.15.3-0ubuntu0.13.10.1
released
raring
Fixed 2:3.15.3-0ubuntu0.13.04.1
released
quantal
Fixed 3.15.3-0ubuntu0.12.10.1
released
precise
Fixed 3.15.3-0ubuntu0.12.04.1
released
lucid
Fixed 3.15.3-0ubuntu0.10.04.1
released
Common Weakness Enumeration
References