CVE-2010-3170
published 2010-10-21CVE-2010-3170: Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 recognize a wildcard IP…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.10%
61.9th percentile
Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 recognize a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
Affected
211 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nss | < nss 3.12.8-1 (bookworm) | nss 3.12.8-1 (bookworm) |
| mozilla | firefox | <= 3.5.13 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
NSS vulnerabilities
vendor_ubuntu·2010-10-20·CVSS 4.3
CVE-2010-3170 [MEDIUM] NSS vulnerabilities
Title: NSS vulnerabilities
Summary: An attacker could view sensitive information in an unlikely circumstance.
Richard Moore discovered that NSS would sometimes incorrectly match an SSL
certificate which had a Common Name that used a wildcard followed by a partial
IP address. While it is very unlikely that a Certificate Authority would issue
such a certificate, if an attacker were able to perform a machine-in-the-middle
attack, this flaw could be exploited to view sensitive information.
(CVE-2010-3170)
Nelson Bolyard discovered a weakness in the Diffie-Hellman Ephemeral mode
(DHE) key exchange implementation which allowed servers to use a too small
key length. (CVE-2010-3173)
Instructions: After a standard system update you need to restart any applications that
use NSS, such as Firefox,
Red Hat
firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely
vendor_redhat·2010-07-14·CVSS 4.3
CVE-2010-3170 [MEDIUM] firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely
firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely
Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 recognize a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
Debian
CVE-2010-3170: nss - Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 ...
vendor_debian·2010·CVSS 4.3
CVE-2010-3170 [MEDIUM] CVE-2010-3170: nss - Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 ...
Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 recognize a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
Scope: local
bookworm: resolved (fixed in 3.12.8-1)
bullseye: resolved (fixed in 3.12.8-1)
forky: resolved (fixed in 3.12.8-1)
sid: resolved (fixed in 3.12.8-1)
trixie: resolved (fixed in 3.12.8-1)
GHSA
GHSA-73h9-xvxv-frc7: Mozilla Firefox before 3
ghsa_unreviewed·2022-05-17
CVE-2010-3170 [MEDIUM] GHSA-73h9-xvxv-frc7: Mozilla Firefox before 3
Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 recognize a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
OSV
CVE-2010-3170: Mozilla Firefox before 3
osv·2010-10-21·CVSS 4.3
CVE-2010-3170 [MEDIUM] CVE-2010-3170: Mozilla Firefox before 3
Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 recognize a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0139 curl: IP address wildcard certificate validation issue in libcurl
bugzilla·2014-03-21·CVSS 4.3
CVE-2014-0139 [MEDIUM] CVE-2014-0139 curl: IP address wildcard certificate validation issue in libcurl
CVE-2014-0139 curl: IP address wildcard certificate validation issue in libcurl
Daniel Stenberg reported the following vulnerability in cURL:
libcurl incorrectly validates wildcard SSL certificates containing literal
IP addresses.
RFC 2818 covers the requirements for matching Common Names (CNs) and
subjectAltNames in order to establish valid SSL connections. It first
discusses CNs that are for hostnames, and the rules for wildcards in this
case. The next paragraph in the RFC then discusses CNs that are IP
addresses:
'In some cases, the URI is specified as an IP address rather than a
hostname. In this case, the iPAddress subjectAltName must be present in the
certificate and must exactly match the IP in the URI.'
The intention of the RFC is clear in that you should not be able to use
wi
Bugzilla
CVE-2010-3170 firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely
bugzilla·2010-09-03·CVSS 5.9
CVE-2010-3170 [MEDIUM] CVE-2010-3170 firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely
CVE-2010-3170 firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely
Richard Moore and Simon Ward reported flaws in the way browsers such
as Firefox handled wildcard characters in the Common Name field of
a certificate. If an attacker is able to get a carefully-crafted certificate,
signed by a Certificate Authority trusted by Firefox, the attacker could
use the certificate during the man-in-the-middle attack and potentially
confuse Firefox into accepting it by mistake. Different vulnerability than
CVE-2009-2408.
References:
[1] http://www.westpoint.ltd.uk/advisories/wp-10-0001.txt
[2] http://bugs.gentoo.org/show_bug.cgi?id=335731
Discussion:
This will be fixed in NSS 3.12.8
---
Mozilla has assigned CVE-2010-3170 identifier to this issue.
Mozilla upstream bug:
[3]
http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefoxhttp://lists.opensuse.org/opensuse-security-announce/2010-11/msg00001.htmlhttp://secunia.com/advisories/41839http://secunia.com/advisories/42867http://support.avaya.com/css/P8/documents/100114250http://support.avaya.com/css/P8/documents/100120156http://www.debian.org/security/2010/dsa-2123http://www.mandriva.com/security/advisories?name=MDVSA-2010:210http://www.mozilla.org/security/announce/2010/mfsa2010-70.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0781.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0782.htmlhttp://www.ubuntu.com/usn/USN-1007-1http://www.vupen.com/english/advisories/2011/0061https://bugzilla.mozilla.org/show_bug.cgi?id=578697https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12254http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefoxhttp://lists.opensuse.org/opensuse-security-announce/2010-11/msg00001.htmlhttp://secunia.com/advisories/41839http://secunia.com/advisories/42867http://support.avaya.com/css/P8/documents/100114250http://support.avaya.com/css/P8/documents/100120156http://www.debian.org/security/2010/dsa-2123http://www.mandriva.com/security/advisories?name=MDVSA-2010:210http://www.mozilla.org/security/announce/2010/mfsa2010-70.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0781.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0782.htmlhttp://www.ubuntu.com/usn/USN-1007-1http://www.vupen.com/english/advisories/2011/0061https://bugzilla.mozilla.org/show_bug.cgi?id=578697https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12254
2010-10-21
Published