PT-2011-2072 · Mozilla · Firefox

Vincent Danen

·

Published

2011-06-06

·

Updated

2017-09-19

·

CVE-2011-0082

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions 4.0.x through 4.0.1
Description The issue is related to the X.509 certificate validation functionality, which does not properly implement single-session security exceptions. This might make it easier for remote attackers to spoof an SSL server via an untrusted certificate, potentially leading to local caching of documents from that server.
Recommendations For Mozilla Firefox versions 4.0.x through 4.0.1, update to a version that properly implements single-session security exceptions to resolve the issue.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-0082

Affected Products

Firefox