CVE-2013-5606
published 2013-11-18CVE-2013-5606: The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an…
PriorityP431medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
2.40%
82.2th percentile
The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nss | < nss 2:3.15.3-1 (bookworm) | nss 2:3.15.3-1 (bookworm) |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | nss | >= 0 < 2:3.15.3-1 | 2:3.15.3-1 |
| mozilla | nss | >= 0 < 2:3.15.3-1 | 2:3.15.3-1 |
| mozilla | nss | >= 0 < 2:3.15.3-1 | 2:3.15.3-1 |
| mozilla | nss | >= 0 < 2:3.15.3-1 | 2:3.15.3-1 |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mphq-fg36-pppm: The CERT_VerifyCert function in lib/certhigh/certvfy
ghsa_unreviewed·2022-05-14
CVE-2013-5606 [MEDIUM] GHSA-mphq-fg36-pppm: The CERT_VerifyCert function in lib/certhigh/certvfy
The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate.
OSV
CVE-2013-5606: The CERT_VerifyCert function in lib/certhigh/certvfy
osv·2013-11-18·CVSS 5.8
CVE-2013-5606 [MEDIUM] CVE-2013-5606: The CERT_VerifyCert function in lib/certhigh/certvfy
The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate.
Red Hat
nss: CERT_VerifyCert returns SECSuccess (saying certificate is good) even for bad certificates (MFSA 2013-103)
vendor_redhat·2013-11-19·CVSS 5.8
CVE-2013-5606 [MEDIUM] nss: CERT_VerifyCert returns SECSuccess (saying certificate is good) even for bad certificates (MFSA 2013-103)
nss: CERT_VerifyCert returns SECSuccess (saying certificate is good) even for bad certificates (MFSA 2013-103)
The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate.
Package: nss (Red Hat Enterprise Linux 7) - Not affected
Ubuntu
NSS vulnerabilities
vendor_ubuntu·2013-11-18
CVE-2013-1739 NSS vulnerabilities
Title: NSS vulnerabilities
Summary: Several security issues were fixed in NSS.
Multiple security issues were discovered in NSS. If a user were tricked
into connecting to a malicious server, an attacker could possibly exploit
these to cause a denial of service via application crash, potentially
execute arbitrary code, or lead to information disclosure.
This update also adds TLS v1.2 support to Ubuntu 10.04 LTS, Ubuntu 12.04
LTS, Ubuntu 12.10, and Ubuntu 13.04.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use NSS, such as Evolution and Chromium, to make all the necessary
changes.
Debian
CVE-2013-5606: nss - The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Securi...
vendor_debian·2013·CVSS 5.8
CVE-2013-5606 [MEDIUM] CVE-2013-5606: nss - The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Securi...
The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate.
Scope: local
bookworm: resolved (fixed in 2:3.15.3-1)
bullseye: resolved (fixed in 2:3.15.3-1)
forky: resolved (fixed in 2:3.15.3-1)
sid: resolved (fixed in 2:3.15.3-1)
trixie: resolved (fixed in 2:3.15.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-5605 CVE-2013-5606 CVE-2013-1741 nss: various flaws [fedora-all]
bugzilla·2013-11-19·CVSS 7.5
CVE-2013-5605 [HIGH] CVE-2013-5605 CVE-2013-5606 CVE-2013-1741 nss: various flaws [fedora-all]
CVE-2013-5605 CVE-2013-5606 CVE-2013-1741 nss: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects
Bugzilla
CVE-2013-5606 nss: CERT_VerifyCert returns SECSuccess (saying certificate is good) even for bad certificates (MFSA 2013-103)
bugzilla·2013-11-18·CVSS 5.8
CVE-2013-5606 [MEDIUM] CVE-2013-5606 nss: CERT_VerifyCert returns SECSuccess (saying certificate is good) even for bad certificates (MFSA 2013-103)
CVE-2013-5606 nss: CERT_VerifyCert returns SECSuccess (saying certificate is good) even for bad certificates (MFSA 2013-103)
Mozilla developer Camilo Viecco discovered that if the verifylog feature was used when validating certificates then certificates with incompatible key usage constraints were not rejected. This did not directly affect Firefox but might affect other software using the NSS library
Upstream bug:
https://bugzilla.mozilla.org/show_bug.cgi?id=910438
Upstream patch:
http://hg.mozilla.org/projects/nss/rev/d29898e0981c
Release notes:
https://developer.mozilla.org/en-US/docs/NSS/NSS_3.15.3_release_notes
External Reference:
http://www.mozilla.org/security/announce/2013/mfsa2013-103.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this
Bugzilla
CERT_VerifyCert returns SECSuccess (saying certificate is good) even for bad certificates, when the CERTVerifyLog log parameter is given
bugzilla·2013-08-28
[MEDIUM] CERT_VerifyCert returns SECSuccess (saying certificate is good) even for bad certificates, when the CERTVerifyLog log parameter is given
CERT_VerifyCert returns SECSuccess (saying certificate is good) even for bad certificates, when the CERTVerifyLog log parameter is given
Calling Cert_VerifyCert on a trusted certificate with incompatible keyusages for the usage returns success if the verifylog parameter is not null and failure if the verifylog parameter is not null.
I would prefer to fail always on bad key usages. The issue is on:
http://mxr.mozilla.org/mozilla-central/source/security/nss/lib/certhigh/certvfy.c#1314
notice that if the certificate is trusted it will always exit... but
on a bad key usage with no log, the function would have terminated earlier with fail on:
http://mxr.mozilla.org/mozilla-central/source/security/nss/lib/certhigh/certvfy.c#1303
Discussion:
Created attachment 797073
Return fail if error log
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00080.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1791.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1829.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0041.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://security.gentoo.org/glsa/glsa-201406-19.xmlhttp://www.debian.org/security/2014/dsa-2994http://www.mozilla.org/security/announce/2013/mfsa2013-103.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/63737http://www.ubuntu.com/usn/USN-2030-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=910438https://developer.mozilla.org/docs/NSS/NSS_3.15.3_release_noteshttps://security.gentoo.org/glsa/201504-01http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00080.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1791.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1829.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0041.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://security.gentoo.org/glsa/glsa-201406-19.xmlhttp://www.debian.org/security/2014/dsa-2994http://www.mozilla.org/security/announce/2013/mfsa2013-103.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/63737http://www.ubuntu.com/usn/USN-2030-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=910438https://developer.mozilla.org/docs/NSS/NSS_3.15.3_release_noteshttps://security.gentoo.org/glsa/201504-01
2013-11-18
Published