CVE-2010-3173: High severity firefox vulnerability
The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly set the minimum key length for Diffie-Hellman Ephemeral (DHE) mode, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3173?
CVE-2010-3173 is considered a moderate severity vulnerability due to its potential impact on secure communications.
How do I fix CVE-2010-3173?
To fix CVE-2010-3173, update Mozilla Firefox, Thunderbird, or SeaMonkey to the latest version that is not affected.
Which versions are affected by CVE-2010-3173?
CVE-2010-3173 affects Mozilla Firefox versions prior to 3.5.14, 3.6.x prior to 3.6.11, Thunderbird versions prior to 3.0.9 and 3.1.x prior to 3.1.5, and SeaMonkey versions prior to 2.0.9.
What type of vulnerability is CVE-2010-3173?
CVE-2010-3173 is a cryptography vulnerability that impacts the handling of Diffie-Hellman Ephemeral (DHE) key exchanges.
Who should be concerned about CVE-2010-3173?
Users of Mozilla Firefox, Thunderbird, or SeaMonkey who are running affected versions should be concerned about CVE-2010-3173 and should update their software.