CVE-2010-3173
published 2010-10-21CVE-2010-3173: The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.04%
86.0th percentile
The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly set the minimum key length for Diffie-Hellman Ephemeral (DHE) mode, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.
Affected
211 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nss | < nss 3.12.8-1 (bookworm) | nss 3.12.8-1 (bookworm) |
| mozilla | firefox | <= 3.5.13 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
NSS vulnerabilities
vendor_ubuntu·2010-10-20·CVSS 4.3
CVE-2010-3170 [MEDIUM] NSS vulnerabilities
Title: NSS vulnerabilities
Summary: An attacker could view sensitive information in an unlikely circumstance.
Richard Moore discovered that NSS would sometimes incorrectly match an SSL
certificate which had a Common Name that used a wildcard followed by a partial
IP address. While it is very unlikely that a Certificate Authority would issue
such a certificate, if an attacker were able to perform a machine-in-the-middle
attack, this flaw could be exploited to view sensitive information.
(CVE-2010-3170)
Nelson Bolyard discovered a weakness in the Diffie-Hellman Ephemeral mode
(DHE) key exchange implementation which allowed servers to use a too small
key length. (CVE-2010-3173)
Instructions: After a standard system update you need to restart any applications that
use NSS, such as Firefox,
Red Hat
NSS: insecure Diffie-Hellman key exchange
vendor_redhat·2010-10-19·CVSS 7.5
CVE-2010-3173 [HIGH] NSS: insecure Diffie-Hellman key exchange
NSS: insecure Diffie-Hellman key exchange
The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly set the minimum key length for Diffie-Hellman Ephemeral (DHE) mode, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.
Package: thunderbird (Red Hat Enterprise Linux 4) - Affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Affected
Package: firefox (Red Hat Enterprise Linux 6) - Affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Affected
Debian
CVE-2010-3173: nss - The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11,...
vendor_debian·2010·CVSS 7.5
CVE-2010-3173 [HIGH] CVE-2010-3173: nss - The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11,...
The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly set the minimum key length for Diffie-Hellman Ephemeral (DHE) mode, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.
Scope: local
bookworm: resolved (fixed in 3.12.8-1)
bullseye: resolved (fixed in 3.12.8-1)
forky: resolved (fixed in 3.12.8-1)
sid: resolved (fixed in 3.12.8-1)
trixie: resolved (fixed in 3.12.8-1)
GHSA
GHSA-qx2q-p5g3-ww8g: The SSL implementation in Mozilla Firefox before 3
ghsa_unreviewed·2022-05-17
CVE-2010-3173 [HIGH] GHSA-qx2q-p5g3-ww8g: The SSL implementation in Mozilla Firefox before 3
The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly set the minimum key length for Diffie-Hellman Ephemeral (DHE) mode, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.
OSV
CVE-2010-3173: The SSL implementation in Mozilla Firefox before 3
osv·2010-10-21·CVSS 7.5
CVE-2010-3173 [HIGH] CVE-2010-3173: The SSL implementation in Mozilla Firefox before 3
The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly set the minimum key length for Diffie-Hellman Ephemeral (DHE) mode, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-3173 NSS: insecure Diffie-Hellman key exchange
bugzilla·2010-10-12·CVSS 7.5
CVE-2010-3173 [HIGH] CVE-2010-3173 NSS: insecure Diffie-Hellman key exchange
CVE-2010-3173 NSS: insecure Diffie-Hellman key exchange
Mozilla cryptographer Nelson Bolyard reported that the SSL implementation
was permitting servers to use 256-bit Diffie-Hellman Ephemeral mode (DHE)
for key exchanges. A DHE key of this length is trivially breakable on
modern hardware so SSL servers operating in this mode were providing very
little effective security for its clients.
Discussion:
This is now public:
http://www.mozilla.org/security/announce/2010/mfsa2010-72.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 4
Via RHSA-2010:0781 https://rhn.redhat.com/errata/RHSA-2010-0781.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-201
arXiv
Graphene: Infrastructure Security Posture Analysis with AI-generated Attack Graphs
arxiv_fulltext·2024-05-01
Graphene: Infrastructure Security Posture Analysis with AI-generated Attack Graphs
: A Holistic Security Posture Analyzer for Edge Computing
Xin Jin, Charalampos Katsis, Fan Sang, Jiahao Sun, Ashish Kundu, Ramana Kompella
xijin3, ckatsis, fsang, jiahasun, ashkundu, [email protected]
Cisco Research
San Jose
California
USA
43017-6221
Trovato et al.
## Abstract
is a system that aims to analyze the security posture of an edge infrastructure thoroughly. The user provides necessary information for the given infrastructure, such as device information and connections, and performs a security analysis that involves finding associated vulnerabilities and using vulnerability knowledge to construct attack paths that an adversary may leverage. In addition, investigates how likely are those paths exploitable and quantifies the overall security posture of the system using a scor
http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefoxhttp://secunia.com/advisories/41839http://secunia.com/advisories/42867http://support.avaya.com/css/P8/documents/100114250http://support.avaya.com/css/P8/documents/100120156http://www.debian.org/security/2010/dsa-2123http://www.mandriva.com/security/advisories?name=MDVSA-2010:210http://www.mandriva.com/security/advisories?name=MDVSA-2010:211http://www.mozilla.org/security/announce/2010/mfsa2010-72.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0781.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0782.htmlhttp://www.ubuntu.com/usn/USN-1007-1http://www.vupen.com/english/advisories/2011/0061https://bugzilla.mozilla.org/show_bug.cgi?id=554354https://bugzilla.mozilla.org/show_bug.cgi?id=583337https://bugzilla.mozilla.org/show_bug.cgi?id=587234https://bugzilla.mozilla.org/show_bug.cgi?id=595300https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12118http://blogs.sun.com/security/entry/multiple_vulnerabilities_in_mozilla_firefoxhttp://secunia.com/advisories/41839http://secunia.com/advisories/42867http://support.avaya.com/css/P8/documents/100114250http://support.avaya.com/css/P8/documents/100120156http://www.debian.org/security/2010/dsa-2123http://www.mandriva.com/security/advisories?name=MDVSA-2010:210http://www.mandriva.com/security/advisories?name=MDVSA-2010:211http://www.mozilla.org/security/announce/2010/mfsa2010-72.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0781.htmlhttp://www.redhat.com/support/errata/RHSA-2010-0782.htmlhttp://www.ubuntu.com/usn/USN-1007-1http://www.vupen.com/english/advisories/2011/0061https://bugzilla.mozilla.org/show_bug.cgi?id=554354https://bugzilla.mozilla.org/show_bug.cgi?id=583337https://bugzilla.mozilla.org/show_bug.cgi?id=587234https://bugzilla.mozilla.org/show_bug.cgi?id=595300https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12118
2010-10-21
Published