CVE-2013-6628

EUVD-2013-6430
net/socket/ssl_client_socket_nss.cc in the TLS implementation in Google Chrome before 31.0.1650.48 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which might allow remote web servers to interfere with trust relationships by renegotiating a session.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 62%
Affected Products (NVD)
VendorProductVersion
googlechrome
𝑥
≤ 31.0.1650.47
googlechrome
31.0.1650.0
googlechrome
31.0.1650.2
googlechrome
31.0.1650.3
googlechrome
31.0.1650.4
googlechrome
31.0.1650.5
googlechrome
31.0.1650.6
googlechrome
31.0.1650.7
googlechrome
31.0.1650.8
googlechrome
31.0.1650.9
googlechrome
31.0.1650.10
googlechrome
31.0.1650.11
googlechrome
31.0.1650.12
googlechrome
31.0.1650.13
googlechrome
31.0.1650.14
googlechrome
31.0.1650.15
googlechrome
31.0.1650.16
googlechrome
31.0.1650.17
googlechrome
31.0.1650.18
googlechrome
31.0.1650.19
googlechrome
31.0.1650.20
googlechrome
31.0.1650.22
googlechrome
31.0.1650.23
googlechrome
31.0.1650.25
googlechrome
31.0.1650.26
googlechrome
31.0.1650.27
googlechrome
31.0.1650.28
googlechrome
31.0.1650.29
googlechrome
31.0.1650.30
googlechrome
31.0.1650.31
googlechrome
31.0.1650.32
googlechrome
31.0.1650.33
googlechrome
31.0.1650.34
googlechrome
31.0.1650.35
googlechrome
31.0.1650.36
googlechrome
31.0.1650.37
googlechrome
31.0.1650.38
googlechrome
31.0.1650.39
googlechrome
31.0.1650.41
googlechrome
31.0.1650.42
googlechrome
31.0.1650.43
googlechrome
31.0.1650.44
googlechrome
31.0.1650.45
googlechrome
31.0.1650.46
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
lucid
ignored
precise
Fixed 31.0.1650.63-0ubuntu0.12.04.1~20131204.1
released
quantal
Fixed 31.0.1650.63-0ubuntu0.12.10.1~20131204.1
released
raring
Fixed 31.0.1650.63-0ubuntu0.13.04.1~20131204.1
released
saucy
Fixed 31.0.1650.63-0ubuntu0.13.10.1~20131204.1
released