cve/2013/CVE-2013-1740.md
2024-06-18 02:51:15 +02:00

1.2 KiB

CVE-2013-1740

Description

The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certificate during certain handshake traffic.

POC

Reference

Github

No PoCs found on GitHub currently.