Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-1739

Опубликовано: 17 окт. 2013
Источник: redhat
CVSS2: 4.3

Описание

Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure.

Отчет

This issue affects the version of nss as shipped with Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this issue as having moderate security impact, a future update may address this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7nssNot affected
Red Hat Enterprise Linux 5nsprFixedRHSA-2013:179105.12.2013
Red Hat Enterprise Linux 5nssFixedRHSA-2013:179105.12.2013
Red Hat Enterprise Linux 6nsprFixedRHSA-2013:182912.12.2013
Red Hat Enterprise Linux 6nssFixedRHSA-2013:182912.12.2013
Red Hat Enterprise Linux 6nss-utilFixedRHSA-2013:182912.12.2013

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1012740nss: Avoid uninitialized data read in the event of a decryption failure

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 12 лет назад

Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure.

nvd
почти 12 лет назад

Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure.

debian
почти 12 лет назад

Mozilla Network Security Services (NSS) before 3.15.2 does not ensure ...

github
больше 3 лет назад

Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure.

fstec
почти 12 лет назад

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить доступность защищаемой информации

4.3 Medium

CVSS2