4
CVE-2013-4566
- EPSS 2%
- Veröffentlicht 12.12.2013 18:55:10
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Erkennungen
mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVerifyClient setting in the directory context, which allows remote attackers to bypass intended access restrictions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mod Nss Project ≫ Mod Nss Version <= 1.0.8
Mod Nss Project ≫ Mod Nss Version 1.0
Mod Nss Project ≫ Mod Nss Version 1.0.2
Mod Nss Project ≫ Mod Nss Version 1.0.3
Mod Nss Project ≫ Mod Nss Version 1.0.4
Mod Nss Project ≫ Mod Nss Version 1.0.5
Mod Nss Project ≫ Mod Nss Version 1.0.6
Mod Nss Project ≫ Mod Nss Version 1.0.7
Redhat ≫ Enterprise Linux Version 5
Redhat ≫ Enterprise Linux Version 6.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2% | 0.782 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4 | 4.9 | 4.9 |
AV:N/AC:H/Au:N/C:P/I:P/A:N
|
http://lists.opensuse.org/opensuse-updates/2013-12/msg00118.html
http://rhn.redhat.com/errata/RHSA-2013-1779.html
https://bugzilla.redhat.com/show_bug.cgi?id=1016832