{"id":"DEBIAN-CVE-2013-5606","details":"The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate.","modified":"2026-09-01T20:03:18.497247156Z","published":"2013-11-18T05:23:57.660Z","upstream":["CVE-2013-5606"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2013-5606"}],"affected":[{"package":{"name":"nss","ecosystem":"Debian:12","purl":"pkg:deb/debian/nss?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.15.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2013-5606.json"}},{"package":{"name":"nss","ecosystem":"Debian:13","purl":"pkg:deb/debian/nss?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.15.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2013-5606.json"}},{"package":{"name":"nss","ecosystem":"Debian:14","purl":"pkg:deb/debian/nss?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:3.15.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2013-5606.json"}}],"schema_version":"1.9.0"}