[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2014:012 -- Mandriva nss

ID: oval:org.secpod.oval:def:1300267Date: (C)2014-01-24   (M)2024-02-19
Class: PATCHFamily: unix




A vulnerability has been discovered and corrected in Mozilla NSS: The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certificate during certain handshake traffic . The updated packages have been upgraded to the 3.15.4 version which is not vulnerable to this issue.

Platform:
Mandriva Enterprise Server 5.2
Product:
nss
Reference:
MDVSA-2014:012
CVE-2013-1740
CVE    1
CVE-2013-1740
CPE    1
cpe:/o:mandriva:enterprise_server:5.2

© SecPod Technologies