Back

MEDIUM

Mozilla: Trust settings for built-in roots ignored during EV certificate validation (MFSA 2013-113)

Published Dec 11, 2013

Description

Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 do not recognize a user's removal of trust from an EV X.509 certificate, which makes it easier for man-in-the-middle attackers to spoof SSL servers in opportunistic circumstances via a valid certificate that is unacceptable to the user.

Affected products

Remediation

Red Hat statement

Not Vulnerable. This issue does not affect the version of firefox and thunderbrid shipped with Red Hat Enterprise Linux 5 and 6.

Metrics

Weaknesses (1)

References (25)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Dec 11, 2013
Updated Aug 6, 2024
Reserved Nov 5, 2013
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 10, 2013