Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-6659


The SSLClientSocketNSS::Core::OwnAuthCertHandler function in net/socket/ssl_client_socket_nss.cc in Google Chrome before 33.0.1750.117 does not prevent changes to server X.509 certificates during renegotiations, which allows remote SSL servers to trigger use of a new certificate chain, inconsistent with the user's expectations, by initiating a TLS renegotiation.


Published

2014-02-24T04:48:10.100

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.4 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-310

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application google chrome ≤ 33.0.1750.116 Yes
Application google chrome 33.0.1750.0 Yes
Application google chrome 33.0.1750.1 Yes
Application google chrome 33.0.1750.2 Yes
Application google chrome 33.0.1750.3 Yes
Application google chrome 33.0.1750.4 Yes
Application google chrome 33.0.1750.5 Yes
Application google chrome 33.0.1750.6 Yes
Application google chrome 33.0.1750.7 Yes
Application google chrome 33.0.1750.8 Yes
Application google chrome 33.0.1750.9 Yes
Application google chrome 33.0.1750.10 Yes
Application google chrome 33.0.1750.11 Yes
Application google chrome 33.0.1750.12 Yes
Application google chrome 33.0.1750.13 Yes
Application google chrome 33.0.1750.14 Yes
Application google chrome 33.0.1750.15 Yes
Application google chrome 33.0.1750.16 Yes
Application google chrome 33.0.1750.18 Yes
Application google chrome 33.0.1750.19 Yes
Application google chrome 33.0.1750.20 Yes
Application google chrome 33.0.1750.21 Yes
Application google chrome 33.0.1750.22 Yes
Application google chrome 33.0.1750.23 Yes
Application google chrome 33.0.1750.24 Yes
Application google chrome 33.0.1750.25 Yes
Application google chrome 33.0.1750.26 Yes
Application google chrome 33.0.1750.27 Yes
Application google chrome 33.0.1750.28 Yes
Application google chrome 33.0.1750.29 Yes
Application google chrome 33.0.1750.30 Yes
Application google chrome 33.0.1750.31 Yes
Application google chrome 33.0.1750.34 Yes
Application google chrome 33.0.1750.35 Yes
Application google chrome 33.0.1750.36 Yes
Application google chrome 33.0.1750.37 Yes
Application google chrome 33.0.1750.38 Yes
Application google chrome 33.0.1750.39 Yes
Application google chrome 33.0.1750.40 Yes
Application google chrome 33.0.1750.41 Yes
Application google chrome 33.0.1750.42 Yes
Application google chrome 33.0.1750.43 Yes
Application google chrome 33.0.1750.44 Yes
Application google chrome 33.0.1750.45 Yes
Application google chrome 33.0.1750.46 Yes
Application google chrome 33.0.1750.47 Yes
Application google chrome 33.0.1750.48 Yes
Application google chrome 33.0.1750.49 Yes
Application google chrome 33.0.1750.50 Yes
Application google chrome 33.0.1750.51 Yes
Application google chrome 33.0.1750.52 Yes
Application google chrome 33.0.1750.53 Yes
Application google chrome 33.0.1750.54 Yes
Application google chrome 33.0.1750.55 Yes
Application google chrome 33.0.1750.56 Yes
Application google chrome 33.0.1750.57 Yes
Application google chrome 33.0.1750.58 Yes
Application google chrome 33.0.1750.59 Yes
Application google chrome 33.0.1750.60 Yes
Application google chrome 33.0.1750.61 Yes
Application google chrome 33.0.1750.62 Yes
Application google chrome 33.0.1750.63 Yes
Application google chrome 33.0.1750.64 Yes
Application google chrome 33.0.1750.65 Yes
Application google chrome 33.0.1750.66 Yes
Application google chrome 33.0.1750.67 Yes
Application google chrome 33.0.1750.68 Yes
Application google chrome 33.0.1750.69 Yes
Application google chrome 33.0.1750.70 Yes
Application google chrome 33.0.1750.71 Yes
Application google chrome 33.0.1750.73 Yes
Application google chrome 33.0.1750.74 Yes
Application google chrome 33.0.1750.75 Yes
Application google chrome 33.0.1750.76 Yes
Application google chrome 33.0.1750.77 Yes
Application google chrome 33.0.1750.79 Yes
Application google chrome 33.0.1750.80 Yes
Application google chrome 33.0.1750.81 Yes
Application google chrome 33.0.1750.82 Yes
Application google chrome 33.0.1750.83 Yes
Application google chrome 33.0.1750.85 Yes
Application google chrome 33.0.1750.88 Yes
Application google chrome 33.0.1750.89 Yes
Application google chrome 33.0.1750.90 Yes
Application google chrome 33.0.1750.91 Yes
Application google chrome 33.0.1750.92 Yes
Application google chrome 33.0.1750.93 Yes
Application google chrome 33.0.1750.104 Yes
Application google chrome 33.0.1750.106 Yes
Application google chrome 33.0.1750.107 Yes
Application google chrome 33.0.1750.108 Yes
Application google chrome 33.0.1750.109 Yes
Application google chrome 33.0.1750.110 Yes
Application google chrome 33.0.1750.111 Yes
Application google chrome 33.0.1750.112 Yes
Application google chrome 33.0.1750.113 Yes
Application google chrome 33.0.1750.115 Yes

References