MGASA-2013-0381

Source
https://advisories.mageia.org/MGASA-2013-0381.html
Import Source
https://advisories.mageia.org/MGASA-2013-0381.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2013-0381
Upstream
  • CVE-2013-4566
Published
2013-12-20T17:27:18Z
Modified
2026-04-16T06:22:52.984646305Z
Summary
Updated apache-mod_nss package fixes CVE-2013-4566
Details

Updated apache-mod_nss package fixes security vulnerability:

A flaw was found in the way modnss handled the NSSVerifyClient setting for the per-directory context. When configured to not require a client certificate for the initial connection and only require it for a specific directory, modnss failed to enforce this requirement and allowed a client to access the directory when no valid client certificate was provided (CVE-2013-4566).

References
Credits

Affected packages

Mageia:3 / apache-mod_nss

Package

Name
apache-mod_nss
Purl
pkg:rpm/mageia/apache-mod_nss?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.8-16.4.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2013-0381.json"