VDB
DEBIAN-CVE-2013-1740
DEBIAN-CVE-2013-1740
PUBLISHED
The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certificate during certain handshake traffic.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:12 | nss | 0, 0, 0 |
| Debian:13 | nss | 0, 0, 0 |
| Debian:14 | nss | 0, 0, 0 |
| Debian:11 | nss | 0, 0, 0 |
Timeline
- Jan 18, 2014 CVE Published
- Apr 28, 2026 CVE Updated