Rapid7 Vulnerability & Exploit Database

MFSA2011-11: Update to HTTPS certificate blacklist

Back to Search

MFSA2011-11: Update to HTTPS certificate blacklist

Severity
6
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:N)
Published
03/21/2011
Created
07/25/2018
Added
04/01/2011
Modified
07/22/2012

Description

Users on a compromised network could be directed to sites using the fraudulent certificates and mistake them for the legitimate sites. This could deceive them into revealing personal information such as usernames and passwords. It may also deceive users into downloading malware if they believe it’s coming from a trusted site.

Solution(s)

  • mozilla-firefox-upgrade-3_5_18
  • mozilla-firefox-upgrade-3_6_16

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;