CVE
- Id
- 65553
- CVE No.
- CVE-2013-5606
- Status
- Candidate
- Description
- The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate.
- Phase
- Assigned (20130826)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
639548 | 65553 | CVE-2013-5606 | BUGTRAQ:20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities | View |
639549 | 65553 | CVE-2013-5606 | URL:http://www.securityfocus.com/archive/1/archive/1/534161/100/0/threaded | View |
639550 | 65553 | CVE-2013-5606 | FULLDISC:20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities | View |
639551 | 65553 | CVE-2013-5606 | URL:http://seclists.org/fulldisclosure/2014/Dec/23 | View |
639552 | 65553 | CVE-2013-5606 | CONFIRM:https://bugzilla.mozilla.org/show_bug.cgi?id=910438 | View |
639553 | 65553 | CVE-2013-5606 | CONFIRM:https://developer.mozilla.org/docs/NSS/NSS_3.15.3_release_notes | View |
639554 | 65553 | CVE-2013-5606 | CONFIRM:http://www.mozilla.org/security/announce/2013/mfsa2013-103.html | View |
639555 | 65553 | CVE-2013-5606 | CONFIRM:http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html | View |
639556 | 65553 | CVE-2013-5606 | CONFIRM:http://www.vmware.com/security/advisories/VMSA-2014-0012.html | View |
639557 | 65553 | CVE-2013-5606 | CONFIRM:http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html | View |
639558 | 65553 | CVE-2013-5606 | CONFIRM:http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html | View |
639559 | 65553 | CVE-2013-5606 | CONFIRM:http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html | View |
639560 | 65553 | CVE-2013-5606 | CONFIRM:http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761 | View |
639561 | 65553 | CVE-2013-5606 | DEBIAN:DSA-2994 | View |
639562 | 65553 | CVE-2013-5606 | URL:http://www.debian.org/security/2014/dsa-2994 | View |
639563 | 65553 | CVE-2013-5606 | GENTOO:GLSA-201406-19 | View |
639564 | 65553 | CVE-2013-5606 | URL:http://security.gentoo.org/glsa/glsa-201406-19.xml | View |
639565 | 65553 | CVE-2013-5606 | GENTOO:GLSA-201504-01 | View |
639566 | 65553 | CVE-2013-5606 | URL:https://security.gentoo.org/glsa/201504-01 | View |
639567 | 65553 | CVE-2013-5606 | REDHAT:RHSA-2013:1791 | View |
639568 | 65553 | CVE-2013-5606 | URL:http://rhn.redhat.com/errata/RHSA-2013-1791.html | View |
639569 | 65553 | CVE-2013-5606 | REDHAT:RHSA-2013:1829 | View |
639570 | 65553 | CVE-2013-5606 | URL:http://rhn.redhat.com/errata/RHSA-2013-1829.html | View |
639571 | 65553 | CVE-2013-5606 | REDHAT:RHSA-2014:0041 | View |
639572 | 65553 | CVE-2013-5606 | URL:http://rhn.redhat.com/errata/RHSA-2014-0041.html | View |
639573 | 65553 | CVE-2013-5606 | SUSE:SUSE-SU-2013:1807 | View |
639574 | 65553 | CVE-2013-5606 | URL:http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00000.html | View |
639575 | 65553 | CVE-2013-5606 | SUSE:openSUSE-SU-2013:1732 | View |
639576 | 65553 | CVE-2013-5606 | URL:http://lists.opensuse.org/opensuse-updates/2013-11/msg00080.html | View |
639577 | 65553 | CVE-2013-5606 | UBUNTU:USN-2030-1 | View |
639578 | 65553 | CVE-2013-5606 | URL:http://www.ubuntu.com/usn/USN-2030-1 | View |
639579 | 65553 | CVE-2013-5606 | BID:63737 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
23903 | JVNDB-2013-005478 | Mozilla Firefox の Web App インストレーションサイトになりすまされる脆弱性 | Mozilla Firefox は、アプリケーションインストール確認 UI のドアハンガー (doorhanger) を適切に削除しないため、Web App インストレーションサイトになりすまされる脆弱性が存在します。 | CVE-2013-5611 | 65553 | 5.8 | http://jvndb.jvn.jp/ja/contents/2013/JVNDB-2013-005478.html | View |