CVE-2013-6673

Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 do not recognize a user's removal of trust from an EV X.509 certificate, which makes it easier for man-in-the-middle attackers to spoof SSL servers in opportunistic circumstances via a valid certificate that is unacceptable to the user.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
mozillaCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 63%
VendorProductVersion
mozillafirefox
𝑥
< 26.0
mozillafirefox_esr
24.0 ≤
𝑥
< 24.2
mozillaseamonkey
𝑥
< 2.23
mozillathunderbird
𝑥
< 24.2
susesuse_linux_enterprise_software_development_kit
11.0:sp3
opensuseopensuse
12.2
opensuseopensuse
12.3
opensuseopensuse
13.1
canonicalubuntu_linux
12.04
canonicalubuntu_linux
12.10
canonicalubuntu_linux
13.04
canonicalubuntu_linux
13.10
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
saucy
Fixed 26.0+build2-0ubuntu0.13.10.2
released
raring
Fixed 26.0+build2-0ubuntu0.13.04.2
released
quantal
Fixed 26.0+build2-0ubuntu0.12.10.2
released
precise
Fixed 26.0+build2-0ubuntu0.12.04.2
released
lucid
ignored
thunderbird
saucy
Fixed 1:24.2.0+build1-0ubuntu0.13.10.1
released
raring
Fixed 1:24.2.0+build1-0ubuntu0.13.04.1
released
quantal
Fixed 1:24.2.0+build1-0ubuntu0.12.10.1
released
precise
Fixed 1:24.2.0+build1-0ubuntu0.12.04.1
released
lucid
ignored
Common Weakness Enumeration
References