Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-1739

Опубликовано: 17 окт. 2013
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure.

Отчет

This issue affects the version of nss as shipped with Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this issue as having moderate security impact, a future update may address this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7nssNot affected
Red Hat Enterprise Linux 5nsprFixedRHSA-2013:179105.12.2013
Red Hat Enterprise Linux 5nssFixedRHSA-2013:179105.12.2013
Red Hat Enterprise Linux 6nsprFixedRHSA-2013:182912.12.2013
Red Hat Enterprise Linux 6nssFixedRHSA-2013:182912.12.2013
Red Hat Enterprise Linux 6nss-utilFixedRHSA-2013:182912.12.2013

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1012740nss: Avoid uninitialized data read in the event of a decryption failure

EPSS

Процентиль: 85%
0.02647
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
около 12 лет назад

Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure.

nvd
около 12 лет назад

Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure.

debian
около 12 лет назад

Mozilla Network Security Services (NSS) before 3.15.2 does not ensure ...

github
больше 3 лет назад

Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure.

fstec
около 12 лет назад

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить доступность защищаемой информации

EPSS

Процентиль: 85%
0.02647
Низкий

4.3 Medium

CVSS2