Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-1544

Опубликовано: 22 июл. 2014
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a trust domain.

A race condition was found in the way NSS verified certain certificates. A remote attacker could use this flaw to crash an application using NSS or, possibly, execute arbitrary code with the privileges of the user running that application.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux Extended Update Support 5.6nssAffected
Red Hat Enterprise Linux 4 Extended Lifecycle SupportnssFixedRHSA-2014:116508.09.2014
Red Hat Enterprise Linux 5nsprFixedRHSA-2014:091622.07.2014
Red Hat Enterprise Linux 5nssFixedRHSA-2014:091622.07.2014
Red Hat Enterprise Linux 5.6 Long LifenssFixedRHSA-2014:091522.07.2014
Red Hat Enterprise Linux 5.9 Extended Update SupportnssFixedRHSA-2014:091522.07.2014
Red Hat Enterprise Linux 6nsprFixedRHSA-2014:091722.07.2014
Red Hat Enterprise Linux 6nssFixedRHSA-2014:091722.07.2014
Red Hat Enterprise Linux 6nss-utilFixedRHSA-2014:091722.07.2014
Red Hat Enterprise Linux 6.2 Advanced Update SupportnssFixedRHSA-2014:091522.07.2014

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1116198nss: Race-condition in certificate verification can lead to Remote code execution (MFSA 2014-63)

EPSS

Процентиль: 87%
0.03216
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a trust domain.

nvd
около 11 лет назад

Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a trust domain.

debian
около 11 лет назад

Use-after-free vulnerability in the CERT_DestroyCertificate function i ...

github
около 3 лет назад

Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a trust domain.

oracle-oval
около 11 лет назад

ELSA-2014-0916: nss and nspr security update (CRITICAL)

EPSS

Процентиль: 87%
0.03216
Низкий

6.8 Medium

CVSS2