CVE-2010-3170Mozilla Firefox vulnerability

CWE-3109 documents8 sources
Severity
4.3MEDIUMNVD
EPSS
1.2%
top 21.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 21
Latest updateMay 17

Description

Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 recognize a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages4 packages

NVDmozilla/firefox3.5.13+91
NVDmozilla/seamonkey2.0.8+41
NVDmozilla/thunderbird3.0.8+71
Debianmozilla/nss< 3.12.8-1+3

🔴Vulnerability Details

3
GHSA
GHSA-73h9-xvxv-frc7: Mozilla Firefox before 32022-05-17
OSV
CVE-2010-3170: Mozilla Firefox before 32010-10-21
CVEList
CVE-2010-3170: Mozilla Firefox before 32010-10-21

📋Vendor Advisories

3
Ubuntu
NSS vulnerabilities2010-10-20
Red Hat
firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely2010-07-14
Debian
CVE-2010-3170: nss - Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 ...2010

💬Community

2
Bugzilla
CVE-2014-0139 curl: IP address wildcard certificate validation issue in libcurl2014-03-21
Bugzilla
CVE-2010-3170 firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely2010-09-03
CVE-2010-3170 — Mozilla Firefox vulnerability | cvebase