4.3

CVE-2015-2721

Exploit

Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS state machine, which allows man-in-the-middle attackers to defeat cryptographic protection mechanisms by blocking messages, as demonstrated by removing a forward-secrecy property by blocking a ServerKeyExchange message, aka a "SMACK SKIP-TLS" issue.

Data is provided by the National Vulnerability Database (NVD)
CanonicalUbuntu Linux Version12.04 SwEditionlts
CanonicalUbuntu Linux Version14.04 SwEditionlts
CanonicalUbuntu Linux Version14.10
CanonicalUbuntu Linux Version15.04
DebianDebian Linux Version7.0
DebianDebian Linux Version8.0
NovellSuse Linux Enterprise Server Version11 Updatesp4
MozillaNetwork Security Services Version3.19
   MozillaFirefox Version <= 38.1.0
   MozillaFirefox Version31.0
   MozillaFirefox Version31.1.0
   MozillaFirefox Version31.1.1
   MozillaFirefox Version31.3.0
   MozillaFirefox Version31.5.1
   MozillaFirefox Version31.5.2
   MozillaFirefox Version31.5.3
   MozillaFirefox Version38.0
   MozillaFirefox ESR Version31.1
   MozillaFirefox ESR Version31.2
   MozillaFirefox ESR Version31.3
   MozillaFirefox ESR Version31.4
   MozillaFirefox ESR Version31.5
   MozillaFirefox ESR Version31.6.0
   MozillaFirefox ESR Version31.7.0
   MozillaThunderbird Version <= 38.0.1
OracleSolaris Version11.3
OracleVm Server Version3.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.61% 0.691
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
https://bugzilla.mozilla.org/show_bug.cgi?id=1086145
Vendor Advisory
Exploit
VDB Entry
Issue Tracking
https://smacktls.com
Technical Description