CVE-2013-4566
published 2013-12-12CVE-2013-4566: mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVerifyClient setting in the directory…
PriorityP427medium4CVSS 2.0
AVNACHAuNCPIPAN
EPSS
2.00%
78.7th percentile
mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVerifyClient setting in the directory context, which allows remote attackers to bypass intended access restrictions.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mod_nss_project | mod_nss | <= 1.0.8 | — |
| mod_nss_project | mod_nss | — | — |
| mod_nss_project | mod_nss | — | — |
| mod_nss_project | mod_nss | — | — |
| mod_nss_project | mod_nss | — | — |
| mod_nss_project | mod_nss | — | — |
| mod_nss_project | mod_nss | — | — |
| mod_nss_project | mod_nss | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
osv4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c4hv-94wj-93p7: mod_nss 1
ghsa_unreviewed·2022-05-14
CVE-2013-4566 [MEDIUM] GHSA-c4hv-94wj-93p7: mod_nss 1
mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVerifyClient setting in the directory context, which allows remote attackers to bypass intended access restrictions.
OSV
CVE-2013-4566: mod_nss 1
osv·2013-12-12·CVSS 4.0
CVE-2013-4566 [MEDIUM] CVE-2013-4566: mod_nss 1
mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVerifyClient setting in the directory context, which allows remote attackers to bypass intended access restrictions.
Red Hat
mod_nss: incorrect handling of NSSVerifyClient in directory context
vendor_redhat·2013-12-03·CVSS 4.0
CVE-2013-4566 [MEDIUM] mod_nss: incorrect handling of NSSVerifyClient in directory context
mod_nss: incorrect handling of NSSVerifyClient in directory context
mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVerifyClient setting in the directory context, which allows remote attackers to bypass intended access restrictions.
Package: mod_nss (Red Hat Certificate System 8) - Will not fix
Package: fortitude-mod_nss (Red Hat Directory Server 8) - Will not fix
Package: mod_nss (Red Hat Enterprise Linux 7) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4566 mod_nss: incorrect handling of NSSVerifyClient in directory context [fedora-all]
bugzilla·2013-12-03·CVSS 4.0
CVE-2013-4566 [MEDIUM] CVE-2013-4566 mod_nss: incorrect handling of NSSVerifyClient in directory context [fedora-all]
CVE-2013-4566 mod_nss: incorrect handling of NSSVerifyClient in directory context [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please not
Bugzilla
CVE-2013-4566 mod_nss: incorrect handling of NSSVerifyClient in directory context
bugzilla·2013-10-08·CVSS 4.0
CVE-2013-4566 [MEDIUM] CVE-2013-4566 mod_nss: incorrect handling of NSSVerifyClient in directory context
CVE-2013-4566 mod_nss: incorrect handling of NSSVerifyClient in directory context
A flaw was found in the way NSSVerifyClient was handled when used in both server / vhost context as well as directory context (specified either via or directive). If 'NSSVerifyClient none' was set in the server / vhost context (i.e. when server is configured to not request or require client certificate authentication on the initial connection), and client certificate authentication was expected to be required for a specific directory via 'NSSVerifyClient require' setting, mod_nss failed to properly require expected certificate authentication. Remote attacker able to connect to the web server using such mod_nss configuration and without a valid client certificate could possibly use this flaw to access content
http://lists.opensuse.org/opensuse-updates/2013-12/msg00118.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1779.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1016832http://lists.opensuse.org/opensuse-updates/2013-12/msg00118.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1779.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1016832
2013-12-12
Published