Уязвимость состояния гонки (race condition) в libssl в пакете Mozilla Network Security Services (NSS), приводящая к DoS атаке через некорректную замену тикета сессии
Описание
Уязвимость связана с возникновением состояния гонки (race condition) в libssl
в составе Mozilla Network Security Services (NSS), что позволяет злоумышленникам инициировать DoS атаку (use-after-free) или повлечь за собой другие неопределенные последствия. Это достигается при помощи манипуляций, связанных с возобновлением handshake, которое вызывает некорректную замену тикета сессии.
Затронутые версии ПО
- NSS до версии 3.15.4
- Mozilla Firefox до версии 27.0
- Firefox ESR 24.x до версии 24.3
- Thunderbird до версии 24.3
- SeaMonkey до версии 2.24
Тип уязвимости
- Race condition
- DoS атака (use-after-free)
- Возможность других неопределённых последствий
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Broken Link
- Not Applicable
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Одно из
Одно из
Одно из
Одно из
Одно из
EPSS
9.3 Critical
CVSS2
Дефекты
Связанные уязвимости
Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involving a resumption handshake that triggers incorrect replacement of a session ticket.
Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involving a resumption handshake that triggers incorrect replacement of a session ticket.
Race condition in libssl in Mozilla Network Security Services (NSS) be ...
Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involving a resumption handshake that triggers incorrect replacement of a session ticket.
ELSA-2014-1246: nss and nspr security, bug fix, and enhancement update (MODERATE)
EPSS
9.3 Critical
CVSS2