Executive Summary

Informations
Name MDVSA-2013:003 First vendor Publication 2013-01-09
Vendor Mandriva Last vendor Modification 2013-01-09
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

Google reported to Mozilla that TURKTRUST, a certificate authority in Mozillas root program, had mis-issued two intermediate certificates to customers. The issue was not specific to Firefox but there was evidence that one of the certificates was used for man-in-the-middle (MITM) traffic management of domain names that the customer did not legitimately own or control. This issue was resolved by revoking the trust for these specific mis-issued certificates (CVE-2013-0743).

The rootcerts package has been upgraded to address this flaw and the Mozilla NSS package has been rebuilt to pickup the changes.

Original Source

Url : http://www.mandriva.com/security/advisories?name=MDVSA-2013:003

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:17859
 
Oval ID: oval:org.mitre.oval:def:17859
Title: USN-1687-1 -- nss vulnerability
Description: Fraudulent security certificates could allow sensitive information to be exposed when accessing the Internet.
Family: unix Class: patch
Reference(s): USN-1687-1
CVE-2013-0743
Version: 7
Platform(s): Ubuntu 12.10
Ubuntu 12.04
Ubuntu 11.10
Ubuntu 10.04
Product(s): nss
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:17950
 
Oval ID: oval:org.mitre.oval:def:17950
Title: USN-1681-2 -- thunderbird vulnerabilities
Description: Several security issues were fixed in Thunderbird.
Family: unix Class: patch
Reference(s): USN-1681-2
CVE-2013-0769
CVE-2013-0749
CVE-2013-0770
CVE-2013-0760
CVE-2013-0761
CVE-2013-0762
CVE-2013-0763
CVE-2013-0766
CVE-2013-0767
CVE-2013-0771
CVE-2012-5829
CVE-2013-0768
CVE-2013-0759
CVE-2013-0744
CVE-2013-0764
CVE-2013-0745
CVE-2013-0746
CVE-2013-0747
CVE-2013-0748
CVE-2013-0750
CVE-2013-0752
CVE-2013-0757
CVE-2013-0758
CVE-2013-0753
CVE-2013-0754
CVE-2013-0755
CVE-2013-0756
CVE-2013-0743
Version: 7
Platform(s): Ubuntu 12.10
Ubuntu 12.04
Ubuntu 11.10
Ubuntu 10.04
Product(s): thunderbird
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:17969
 
Oval ID: oval:org.mitre.oval:def:17969
Title: USN-1687-2 -- nspr update
Description: NSPR update to work with the new NSS.
Family: unix Class: patch
Reference(s): USN-1687-2
CVE-2013-0743
Version: 7
Platform(s): Ubuntu 12.10
Ubuntu 12.04
Ubuntu 11.10
Ubuntu 10.04
Product(s): nspr
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:18149
 
Oval ID: oval:org.mitre.oval:def:18149
Title: USN-1681-3 -- firefox regression
Description: USN-1681-1 introduced a regression in Firefox.
Family: unix Class: patch
Reference(s): USN-1681-3
CVE-2013-0769
CVE-2013-0749
CVE-2013-0770
CVE-2013-0760
CVE-2013-0761
CVE-2013-0762
CVE-2013-0763
CVE-2013-0766
CVE-2013-0767
CVE-2013-0771
CVE-2012-5829
CVE-2013-0768
CVE-2013-0759
CVE-2013-0744
CVE-2013-0764
CVE-2013-0745
CVE-2013-0746
CVE-2013-0747
CVE-2013-0748
CVE-2013-0750
CVE-2013-0752
CVE-2013-0757
CVE-2013-0758
CVE-2013-0753
CVE-2013-0754
CVE-2013-0755
CVE-2013-0756
CVE-2013-0743
Version: 7
Platform(s): Ubuntu 12.10
Ubuntu 12.04
Ubuntu 11.10
Ubuntu 10.04
Product(s): firefox
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:18249
 
Oval ID: oval:org.mitre.oval:def:18249
Title: USN-1681-1 -- firefox vulnerabilities
Description: Several security issues were fixed in Firefox.
Family: unix Class: patch
Reference(s): USN-1681-1
CVE-2013-0769
CVE-2013-0749
CVE-2013-0770
CVE-2013-0760
CVE-2013-0761
CVE-2013-0762
CVE-2013-0763
CVE-2013-0766
CVE-2013-0767
CVE-2013-0771
CVE-2012-5829
CVE-2013-0768
CVE-2013-0759
CVE-2013-0744
CVE-2013-0764
CVE-2013-0745
CVE-2013-0746
CVE-2013-0747
CVE-2013-0748
CVE-2013-0750
CVE-2013-0752
CVE-2013-0757
CVE-2013-0758
CVE-2013-0753
CVE-2013-0754
CVE-2013-0755
CVE-2013-0756
CVE-2013-0743
Version: 7
Platform(s): Ubuntu 12.10
Ubuntu 12.04
Ubuntu 11.10
Ubuntu 10.04
Product(s): firefox
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:18290
 
Oval ID: oval:org.mitre.oval:def:18290
Title: USN-1681-4 -- firefox regression
Description: USN-1681-1 introduced a regression in Firefox.
Family: unix Class: patch
Reference(s): USN-1681-4
CVE-2013-0769
CVE-2013-0749
CVE-2013-0770
CVE-2013-0760
CVE-2013-0761
CVE-2013-0762
CVE-2013-0763
CVE-2013-0766
CVE-2013-0767
CVE-2013-0771
CVE-2012-5829
CVE-2013-0768
CVE-2013-0759
CVE-2013-0744
CVE-2013-0764
CVE-2013-0745
CVE-2013-0746
CVE-2013-0747
CVE-2013-0748
CVE-2013-0750
CVE-2013-0752
CVE-2013-0757
CVE-2013-0758
CVE-2013-0753
CVE-2013-0754
CVE-2013-0755
CVE-2013-0756
CVE-2013-0743
Version: 7
Platform(s): Ubuntu 12.10
Ubuntu 12.04
Ubuntu 11.10
Ubuntu 10.04
Product(s): firefox
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:18476
 
Oval ID: oval:org.mitre.oval:def:18476
Title: DSA-2599-1 nss - mis-issued intermediates
Description: Google, Inc. discovered that the TurkTrust certification authority included in the Network Security Service libraries (nss) mis-issued two intermediate CAs which could be used to generate rogue end-entity certificates. This update explicitly distrusts those two intermediate CAs. The two existing TurkTrust root CAs remain active.
Family: unix Class: patch
Reference(s): DSA-2599-1
CVE-2013-0743
Version: 7
Platform(s): Debian GNU/Linux 6.0
Debian GNU/kFreeBSD 6.0
Product(s): nss
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:25815
 
Oval ID: oval:org.mitre.oval:def:25815
Title: SUSE-SU-2013:0306-1 -- Security update for Mozilla Firefox
Description: Mozilla Firefox is updated to the 10.0.12ESR version. This is a roll-up update for LTSS. It fixes a lot of security issues and bugs.
Family: unix Class: patch
Reference(s): SUSE-SU-2013:0306-1
CVE-2013-0769
CVE-2013-0749
CVE-2013-0770
CVE-2013-0760
CVE-2013-0762
CVE-2013-0766
CVE-2013-0763
CVE-2013-0771
CVE-2012-5829
CVE-2013-0768
CVE-2013-0759
CVE-2013-0744
CVE-2013-0751
CVE-2013-0764
CVE-2013-0745
CVE-2013-0746
CVE-2013-0747
CVE-2013-0748
CVE-2013-0750
CVE-2013-0752
CVE-2013-0757
CVE-2013-0758
CVE-2013-0753
CVE-2013-0754
CVE-2013-0755
CVE-2013-0756
CVE-2013-0743
Version: 5
Platform(s): SUSE Linux Enterprise Server 10
Product(s): Mozilla Firefox
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:26135
 
Oval ID: oval:org.mitre.oval:def:26135
Title: SUSE-SU-2013:0292-1 -- Security update for MozillaFirefox
Description: Mozilla Firefox was updated to the 10.0.12ESR release for LTSS.
Family: unix Class: patch
Reference(s): SUSE-SU-2013:0292-1
CVE-2013-0769
CVE-2013-0749
CVE-2013-0770
CVE-2013-0760
CVE-2013-0762
CVE-2013-0766
CVE-2013-0767
CVE-2013-0761
CVE-2013-0763
CVE-2013-0771
CVE-2012-5829
CVE-2013-0768
CVE-2013-0759
CVE-2013-0744
CVE-2013-0751
CVE-2013-0764
CVE-2013-0745
CVE-2013-0746
CVE-2013-0747
CVE-2013-0748
CVE-2013-0750
CVE-2013-0752
CVE-2013-0757
CVE-2013-0758
CVE-2013-0753
CVE-2013-0754
CVE-2013-0755
CVE-2013-0756
CVE-2013-0743
Version: 5
Platform(s): SUSE Linux Enterprise Server 11
Product(s): MozillaFirefox
Definition Synopsis:

Nessus® Vulnerability Scanner

Date Description
2015-05-20 Name : The remote SUSE host is missing one or more security updates.
File : suse_SU-2013-0306-1.nasl - Type : ACT_GATHER_INFO
2014-06-13 Name : The remote openSUSE host is missing a security update.
File : openSUSE-2013-17.nasl - Type : ACT_GATHER_INFO
2013-04-20 Name : The remote Mandriva Linux host is missing one or more security updates.
File : mandriva_MDVSA-2013-050.nasl - Type : ACT_GATHER_INFO
2013-02-06 Name : The remote Ubuntu host is missing a security-related patch.
File : ubuntu_USN-1681-4.nasl - Type : ACT_GATHER_INFO
2013-02-04 Name : The remote Fedora host is missing a security update.
File : fedora_2013-1432.nasl - Type : ACT_GATHER_INFO
2013-02-04 Name : The remote Fedora host is missing a security update.
File : fedora_2013-1382.nasl - Type : ACT_GATHER_INFO
2013-01-28 Name : The remote Fedora host is missing a security update.
File : fedora_2013-1442.nasl - Type : ACT_GATHER_INFO
2013-01-25 Name : The remote SuSE 11 host is missing one or more security updates.
File : suse_11_firefox-201301-130110.nasl - Type : ACT_GATHER_INFO
2013-01-23 Name : The remote Ubuntu host is missing a security-related patch.
File : ubuntu_USN-1681-3.nasl - Type : ACT_GATHER_INFO
2013-01-20 Name : The remote SuSE 10 host is missing a security-related patch.
File : suse_firefox-201301-8426.nasl - Type : ACT_GATHER_INFO
2013-01-15 Name : The remote Windows host contains a mail client that is potentially affected b...
File : mozilla_thunderbird_1702.nasl - Type : ACT_GATHER_INFO
2013-01-15 Name : The remote Mac OS X host contains a web browser that is affected by multiple ...
File : macosx_firefox_10_0_12.nasl - Type : ACT_GATHER_INFO
2013-01-15 Name : The remote Windows host contains a web browser that is affected by multiple v...
File : seamonkey_215.nasl - Type : ACT_GATHER_INFO
2013-01-15 Name : The remote Mac OS X host contains a web browser that is affected by multiple ...
File : macosx_firefox_18_0.nasl - Type : ACT_GATHER_INFO
2013-01-15 Name : The remote Windows host contains a mail client that is potentially affected b...
File : mozilla_thunderbird_10012.nasl - Type : ACT_GATHER_INFO
2013-01-15 Name : The remote Windows host contains a web browser that is affected by multiple v...
File : mozilla_firefox_180.nasl - Type : ACT_GATHER_INFO
2013-01-15 Name : The remote Windows host contains a web browser that is affected by multiple v...
File : mozilla_firefox_1702.nasl - Type : ACT_GATHER_INFO
2013-01-15 Name : The remote Windows host contains a web browser that is affected by multiple v...
File : mozilla_firefox_10012.nasl - Type : ACT_GATHER_INFO
2013-01-15 Name : The remote Mac OS X host contains a web browser that is affected by multiple ...
File : macosx_firefox_17_0_2.nasl - Type : ACT_GATHER_INFO
2013-01-15 Name : The remote Mac OS X host contains a mail client that is potentially affected ...
File : macosx_thunderbird_17_0_2.nasl - Type : ACT_GATHER_INFO
2013-01-15 Name : The remote Mac OS X host contains a mail client that is potentially affected ...
File : macosx_thunderbird_10_0_12.nasl - Type : ACT_GATHER_INFO
2013-01-10 Name : The remote Mandriva Linux host is missing one or more security updates.
File : mandriva_MDVSA-2013-003.nasl - Type : ACT_GATHER_INFO
2013-01-09 Name : The remote Ubuntu host is missing a security-related patch.
File : ubuntu_USN-1681-1.nasl - Type : ACT_GATHER_INFO
2013-01-09 Name : The remote Ubuntu host is missing a security-related patch.
File : ubuntu_USN-1681-2.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
2
Date Informations
2014-02-17 11:43:16
  • Multiple Updates
2013-01-25 21:19:35
  • Multiple Updates
2013-01-09 21:18:36
  • First insertion