Back to search
CVE-2018-12384
Published: Apr 29, 2019
Modified: Aug 5, 2024
PUBLISHED
Description
When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead. This results in full malleability of the ClientHello for SSLv2 used for TLS 1.2 in all versions prior to NSS 3.39. This does not impact TLS 1.3.
| Vendor | Product | Versions |
|---|---|---|
NSS | Network Security Services (NSS) | affected All versions prior to NSS 3.39 |
References
https://bugzilla.mozilla.org/show_bug.cgi?id=CVE-2018-12384
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now