PT-2023-36107 · Mozilla · Ca-Certificates-Mozilla
Published
2023-01-06
·
Updated
2023-01-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
ca-certificates-mozilla (affected versions not specified)
Description
The update for ca-certificates-mozilla fixes issues related to the removal and addition of Certificate Authorities (CAs) and changes in trust settings. Specifically, it removes CAs such as Global Chambersign Root, EC-ACC, Network Solutions Certificate Authority, Staat der Nederlanden EV Root CA, and SwissSign Platinum CA - G2, and adds new CAs like DIGITALSIGN GLOBAL ROOT ECDSA CA, DIGITALSIGN GLOBAL ROOT RSA CA, Security Communication ECC RootCA1, and Security Communication RootCA3. The trust for TrustCor certificates is limited to those valid up to November 30. Additionally, some CAs are removed due to issues with handling 'valid before' dates and unclear numbers of issued certificates for SSL middleware by TrustCor.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ca-Certificates-Mozilla