Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-1979

Опубликовано: 13 мар. 2016
Источник: debian

Описание

Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
iceweaselremovedpackage
iceweaselnot-affectedjessiepackage
iceweaselnot-affectedwheezypackage
firefox-esrfixed45.0esr-1package
firefoxfixed45.0-1package
icedovefixed38.8.0-1package
nssfixed2:3.21-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2016-36/

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 10 лет назад

Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.

redhat
почти 10 лет назад

Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.

CVSS3: 8.8
nvd
почти 10 лет назад

Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.

CVSS3: 8.8
github
больше 3 лет назад

Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.

fstec
почти 10 лет назад

Уязвимость набора библиотек Network Security Services, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие