Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
https://bugzilla.mozilla.org/show_bug.cgi?id=249004 http://banquo.inf.ethz.ch:8080/
http://www.vuxml.org/freebsd/8d823883-0ca9-11d9-8a8a-000c41e2cdad.html
Insight
The following packages are affected:
firefox
linux-mozilla
linux-mozilla-devel
mozilla
mozilla-gtk1
CVE-2004-0758
Mozilla 1.5 through 1.7 allows a CA certificate to be imported even when their DN is the same as that of the built-in CA root certificate, which allows remote attackers to cause a denial of service to SSL pages because the malicious certificate is treated as invalid.
Severity
Classification
-
CVE CVE-2004-0758 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities