Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-7181

Опубликовано: 03 нояб. 2015
Источник: redhat
CVSS2: 6.8
EPSS Средний

Описание

The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, improperly restricts access to an unspecified data structure, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data, related to a "use-after-poison" issue.

A use-after-poison flaw was found in the way NSS parsed certain ASN.1 structures. An attacker could use this flaw to cause NSS to crash or execute arbitrary code with the permissions of the user running an application compiled against the NSS library.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4nssWill not fix
Red Hat Enterprise Linux 5nsprFixedRHSA-2015:198004.11.2015
Red Hat Enterprise Linux 5nssFixedRHSA-2015:198004.11.2015
Red Hat Enterprise Linux 6nsprFixedRHSA-2015:198104.11.2015
Red Hat Enterprise Linux 6nssFixedRHSA-2015:198104.11.2015
Red Hat Enterprise Linux 6nss-utilFixedRHSA-2015:198104.11.2015
Red Hat Enterprise Linux 6.2 Advanced Update SupportnsprFixedRHSA-2015:206818.11.2015
Red Hat Enterprise Linux 6.2 Advanced Update SupportnssFixedRHSA-2015:206818.11.2015
Red Hat Enterprise Linux 6.2 Advanced Update Supportnss-utilFixedRHSA-2015:206818.11.2015
Red Hat Enterprise Linux 6.4 Advanced Update SupportnsprFixedRHSA-2015:206818.11.2015

Показывать по

Дополнительная информация

Статус:

Critical
https://bugzilla.redhat.com/show_bug.cgi?id=1269345nss: use-after-poison in sec_asn1d_parse_leaf() (MFSA 2015-133)

EPSS

Процентиль: 96%
0.24811
Средний

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 10 лет назад

The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, improperly restricts access to an unspecified data structure, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data, related to a "use-after-poison" issue.

nvd
почти 10 лет назад

The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, improperly restricts access to an unspecified data structure, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data, related to a "use-after-poison" issue.

debian
почти 10 лет назад

The sec_asn1d_parse_leaf function in Mozilla Network Security Services ...

github
больше 3 лет назад

The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, improperly restricts access to an unspecified data structure, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data, related to a "use-after-poison" issue.

fstec
почти 10 лет назад

Уязвимость браузеров Firefox и Firefox ESR, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код

EPSS

Процентиль: 96%
0.24811
Средний

6.8 Medium

CVSS2