CVE-2013-1740
published 2014-01-18CVE-2013-1740: The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled…
PriorityP428medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
1.93%
77.7th percentile
The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certificate during certain handshake traffic.
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nss | < nss 2:3.15.4-1 (bookworm) | nss 2:3.15.4-1 (bookworm) |
| mozilla | network_security_services | <= 3.15.3 | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
NSS vulnerability
vendor_ubuntu·2014-01-23
CVE-2013-1740 NSS vulnerability
Title: NSS vulnerability
Summary: NSS could be made to expose sensitive information over the network.
Brian Smith discovered that NSS incorrectly handled the TLS False Start
feature. If a remote attacker were able to perform a machine-in-the-middle
attack, this flaw could be exploited to spoof SSL servers.
Instructions: After a standard system update you need to restart any applications that
use NSS, such as Evolution and Chromium, to make all the necessary changes.
Red Hat
nss: false start PR_Recv information disclosure security issue
vendor_redhat·2014-01-05·CVSS 5.8
CVE-2013-1740 [MEDIUM] nss: false start PR_Recv information disclosure security issue
nss: false start PR_Recv information disclosure security issue
The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certificate during certain handshake traffic.
A flaw was found in the way TLS False Start was implemented in NSS. An attacker could use this flaw to potentially return unencrypted information from the server.
Package: nss (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-1740: nss - The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Secur...
vendor_debian·2013·CVSS 5.8
CVE-2013-1740 [MEDIUM] CVE-2013-1740: nss - The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Secur...
The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certificate during certain handshake traffic.
Scope: local
bookworm: resolved (fixed in 2:3.15.4-1)
bullseye: resolved (fixed in 2:3.15.4-1)
forky: resolved (fixed in 2:3.15.4-1)
sid: resolved (fixed in 2:3.15.4-1)
trixie: resolved (fixed in 2:3.15.4-1)
GHSA
GHSA-26rr-whcg-5f4g: The ssl_Do1stHandshake function in sslsecur
ghsa_unreviewed·2022-05-14
CVE-2013-1740 [MEDIUM] GHSA-26rr-whcg-5f4g: The ssl_Do1stHandshake function in sslsecur
The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certificate during certain handshake traffic.
OSV
CVE-2013-1740: The ssl_Do1stHandshake function in sslsecur
osv·2014-01-18·CVSS 5.8
CVE-2013-1740 [MEDIUM] CVE-2013-1740: The ssl_Do1stHandshake function in sslsecur
The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certificate during certain handshake traffic.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1740 nss: false start PR_Recv information disclosure security issue [fedora-all]
bugzilla·2014-01-16·CVSS 5.8
CVE-2013-1740 [MEDIUM] CVE-2013-1740 nss: false start PR_Recv information disclosure security issue [fedora-all]
CVE-2013-1740 nss: false start PR_Recv information disclosure security issue [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: th
Bugzilla
CVE-2013-1740 nss: false start PR_Recv information disclosure security issue
bugzilla·2014-01-15·CVSS 5.8
CVE-2013-1740 [MEDIUM] CVE-2013-1740 nss: false start PR_Recv information disclosure security issue
CVE-2013-1740 nss: false start PR_Recv information disclosure security issue
A security issue has been reported in NSS, which can be exploited by a malicious user to disclose certain information.
The issue arises due to an error within the "ssl_Do1stHandshake()" function in lib/ssl/sslsecur.c, which can be exploited to potentially return unencrypted and unauthenticated data from PR_Recv. Successful exploitation requires false start to be enabled.
The issue is said to be fixed in NSS 3.15.4.
References:
https://bugs.gentoo.org/show_bug.cgi?id=498172
https://developer.mozilla.org/en-US/docs/NSS/NSS_3.15.4_release_notes
Upstream bug:
https://bugzilla.mozilla.org/show_bug.cgi?id=919877
Patch:
https://bugzilla.mozilla.org/attachment.cgi?id=825813
Discussion:
By default, NSS ships with f
Bugzilla
When false start is enabled, libssl will sometimes return unencrypted, unauthenticated data from PR_Recv
bugzilla·2013-09-24
[CRITICAL] When false start is enabled, libssl will sometimes return unencrypted, unauthenticated data from PR_Recv
When false start is enabled, libssl will sometimes return unencrypted, unauthenticated data from PR_Recv
While working on updating strsclnt to actually test false start [1] as part of bug 713933, I added a SSL_TRC call to ssl_SecureSend that would be triggered whenever we are sending data when !ss->isFirstHsDone. However, when running strsclnt, that condition was never true, even when we were false starting. That is because of this code:
> @@ -103,20 +103,22 @@ ssl_Do1stHandshake(sslSocket *ss)
>
> SSL_TRC(3, ("%d: SSL[%d]: handshake is completed",
> SSL_GETPID(), ss->fd));
> /* call handshake callback for ssl v2 */
> /* for v3 this is done in ssl3_HandleFinished() */
> if ((ss->handshakeCallback != NULL) && /* has callback */
> (!ss->firstHsDone) && /* only first time */
> (ss->version
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/64944http://www.ubuntu.com/usn/USN-2088-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://bugs.gentoo.org/show_bug.cgi?id=498172https://bugzilla.mozilla.org/show_bug.cgi?id=919877https://bugzilla.redhat.com/show_bug.cgi?id=1053725https://developer.mozilla.org/docs/NSS/NSS_3.15.4_release_noteshttps://exchange.xforce.ibmcloud.com/vulnerabilities/90394http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00005.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/64944http://www.ubuntu.com/usn/USN-2088-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://bugs.gentoo.org/show_bug.cgi?id=498172https://bugzilla.mozilla.org/show_bug.cgi?id=919877https://bugzilla.redhat.com/show_bug.cgi?id=1053725https://developer.mozilla.org/docs/NSS/NSS_3.15.4_release_noteshttps://exchange.xforce.ibmcloud.com/vulnerabilities/90394
2014-01-18
Published