Vulnerability Name:

CVE-2011-0082 (CCN-67784)

Assigned:2010-12-21
Published:2011-06-01
Updated:2017-09-19
Summary:The X.509 certificate validation functionality in Mozilla Firefox 4.0.x through 4.0.1 does not properly implement single-session security exceptions, which might make it easier for user-assisted remote attackers to spoof an SSL server via an untrusted certificate that triggers potentially unwanted local caching of documents from that server.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.5 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.5 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:UR)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-20
Vulnerability Consequences:Bypass Security
References:Source: CONFIRM
Type: Exploit
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=627552

Source: MITRE
Type: CNA
CVE-2011-0082

Source: MLIST
Type: Exploit
[oss-security] 20110531 Re: CVE request: firefox doesn't (re)validate certificates when loading HTTPS page

Source: MLIST
Type: Exploit
[oss-security] 20110531 Re: CVE request: firefox doesn't (re)validate certificates when loading HTTPS page

Source: MLIST
Type: Exploit
[oss-security] 20110531 CVE request: firefox doesn't (re)validate certificates when loading HTTPS page

Source: MLIST
Type: Exploit
[oss-security] 20110531 Re: CVE request: firefox doesn't (re)validate certificates when loading HTTPS page

Source: CCN
Type: Mozilla Web site
mozilla - home of the mozilla, firefox, and camino web browsers

Source: CCN
Type: OSVDB ID: 74378
Mozilla Firefox X.509 Certificate Validation Single-session Security Exception SSL Server Spoofing Weakness

Source: BID
Type: UNKNOWN
48064

Source: CCN
Type: BID-48064
Mozilla Firefox SSL Certificate Validation Security Weakness

Source: CCN
Type: Bugzilla@Mozilla Bug 660749
(CVE-2011-0082) Firefox doesn't (re)validate certificates when loading HTTPS page

Source: CONFIRM
Type: Exploit
https://bugzilla.mozilla.org/show_bug.cgi?id=660749

Source: CONFIRM
Type: Exploit
https://bugzilla.redhat.com/show_bug.cgi?id=709165

Source: XF
Type: UNKNOWN
mozilla-firefox-ssl-sec-bypass(67784)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:14145

Vulnerable Configuration:Configuration 1:
  • cpe:/a:mozilla:firefox:4.0:*:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:4.0:beta1:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:4.0:beta10:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:4.0:beta11:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:4.0:beta12:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:4.0:beta2:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:4.0:beta3:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:4.0:beta4:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:4.0:beta5:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:4.0:beta6:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:4.0:beta7:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:4.0:beta8:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:4.0:beta9:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:4.0.1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:mozilla:firefox:4.0:beta1:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:4.0:beta2:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:4.0:beta3:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:4.0:beta4:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:4.0:beta5:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:4.0:beta6:*:*:*:*:*:*
  • OR cpe:/a:mozilla:firefox:4.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:14145
    V
    The X.509 certificate validation functionality in Mozilla Firefox 4.0.x through 4.0.1 does not properly implement single-session security exceptions, which might make it easier for user-assisted remote attackers to spoof an SSL server via an untrusted certificate that triggers potentially unwanted local caching of documents from that server.
    2014-10-06
    BACK
    mozilla firefox 4.0
    mozilla firefox 4.0 beta1
    mozilla firefox 4.0 beta10
    mozilla firefox 4.0 beta11
    mozilla firefox 4.0 beta12
    mozilla firefox 4.0 beta2
    mozilla firefox 4.0 beta3
    mozilla firefox 4.0 beta4
    mozilla firefox 4.0 beta5
    mozilla firefox 4.0 beta6
    mozilla firefox 4.0 beta7
    mozilla firefox 4.0 beta8
    mozilla firefox 4.0 beta9
    mozilla firefox 4.0.1
    mozilla firefox 4.0 beta1
    mozilla firefox 4.0 beta2
    mozilla firefox 4.0 beta3
    mozilla firefox 4.0 beta4
    mozilla firefox 4.0 beta5
    mozilla firefox 4.0 beta6
    mozilla firefox 4.0