Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-7183

Опубликовано: 05 нояб. 2015
Источник: debian
EPSS Средний

Описание

Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
iceweaselfixed38.4.0esr-1package
iceweaselend-of-lifesqueezepackage
nsprfixed2:4.10.10-1package
icedovefixed31.7.0-1~deb8u1package
icedoveend-of-lifesqueezepackage
virtualbox-oseremovedpackage
virtualbox-oseend-of-lifesqueezepackage
virtualboxfixed5.0.10-dfsg-1package
virtualboxfixed4.3.36-dfsg-1+deb8u1jessiepackage
virtualboxno-dsawheezypackage

Примечания

  • VirtualBox fixed: 4.0.36, 4.1.44, 4.2.36, 4.3.34, 5.0.10

  • http://hg.mozilla.org/projects/nspr/rev/c9c965b2b19c

  • http://hg.mozilla.org/projects/nspr/rev/bd8fb4498fa6

  • https://www.mozilla.org/en-US/security/advisories/mfsa2015-133/

  • Icedove, virtualbox(-ose)? have embedded copies of nspr.

  • Fixes impact macros PL_ARENA_ALLOCATE and PL_ARENA_GROW, other packages need to be recompiled:

  • jss (on wheezy/jessie) according to codesearch.debian.net

EPSS

Процентиль: 95%
0.18188
Средний

Связанные уязвимости

ubuntu
почти 10 лет назад

Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.

redhat
почти 10 лет назад

Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.

nvd
почти 10 лет назад

Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.

github
больше 3 лет назад

Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.

fstec
почти 10 лет назад

Уязвимость браузеров Firefox и Firefox ESR, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

EPSS

Процентиль: 95%
0.18188
Средний