Hide Forgot
Mozilla developer Camilo Viecco discovered that if the verifylog feature was used when validating certificates then certificates with incompatible key usage constraints were not rejected. This did not directly affect Firefox but might affect other software using the NSS library Upstream bug: https://bugzilla.mozilla.org/show_bug.cgi?id=910438 Upstream patch: http://hg.mozilla.org/projects/nss/rev/d29898e0981c Release notes: https://developer.mozilla.org/en-US/docs/NSS/NSS_3.15.3_release_notes External Reference: http://www.mozilla.org/security/announce/2013/mfsa2013-103.html Acknowledgements: Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Camilo Viecco as the original reporter of this issue.
Created nss tracking bugs for this issue: Affects: fedora-all [bug 1031897]
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2013:1791 https://rhn.redhat.com/errata/RHSA-2013-1791.html
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2013:1829 https://rhn.redhat.com/errata/RHSA-2013-1829.html
This issue has been addressed in following products: RHEV-H and Agents for RHEL-6 Via RHSA-2014:0041 https://rhn.redhat.com/errata/RHSA-2014-0041.html