CVE Published: 29/04/2019 |
CVE Updated: 05/08/2024 |
CVE Year: 2018 Source: mozilla |
Vendor: NSS |
Product: Network Security Services (NSS) Status : PUBLISHED
CVE-2018-12384 Description
When handling a SSLv2-compatible ClientHello request, the server doesn\'t generate a new random value but sends an all-zero value instead. This results in full malleability of the ClientHello for SSLv2 used for TLS 1.2 in all versions prior to NSS 3.39. This does not impact TLS 1.3.