CVE Database
/

CVE-2013-6628

Back to search

CVE-2013-6628

Published: Nov 13, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

net/socket/ssl_client_socket_nss.cc in the TLS implementation in Google Chrome before 31.0.1650.48 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which might allow remote web servers to interfere with trust relationships by renegotiating a session.

VendorProductVersions

n/a

n/a

affected
n/a

References

openSUSE-SU-2014:0065
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2013:1776
vendor-advisory
x_refsource_SUSE
DSA-2799
vendor-advisory
x_refsource_DEBIAN
openSUSE-SU-2013:1861
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2013:1777
vendor-advisory
x_refsource_SUSE
oval:org.mitre.oval:def:19108
vdb-entry
signature
x_refsource_OVAL

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now