Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-7183

Опубликовано: 03 нояб. 2015
Источник: redhat
CVSS2: 6.8
EPSS Средний

Описание

Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.

A heap-based buffer overflow was found in NSPR. An attacker could use this flaw to cause NSPR to crash or execute arbitrary code with the permissions of the user running an application compiled against the NSPR library.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4nsprWill not fix
Red Hat Enterprise Linux 5nsprFixedRHSA-2015:198004.11.2015
Red Hat Enterprise Linux 5nssFixedRHSA-2015:198004.11.2015
Red Hat Enterprise Linux 6nsprFixedRHSA-2015:198104.11.2015
Red Hat Enterprise Linux 6nssFixedRHSA-2015:198104.11.2015
Red Hat Enterprise Linux 6nss-utilFixedRHSA-2015:198104.11.2015
Red Hat Enterprise Linux 6.2 Advanced Update SupportnsprFixedRHSA-2015:206818.11.2015
Red Hat Enterprise Linux 6.2 Advanced Update SupportnssFixedRHSA-2015:206818.11.2015
Red Hat Enterprise Linux 6.2 Advanced Update Supportnss-utilFixedRHSA-2015:206818.11.2015
Red Hat Enterprise Linux 6.4 Advanced Update SupportnsprFixedRHSA-2015:206818.11.2015

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-190->CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1269353nspr: heap-buffer overflow in PL_ARENA_ALLOCATE (MFSA 2015-133)

EPSS

Процентиль: 95%
0.18188
Средний

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 10 лет назад

Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.

nvd
почти 10 лет назад

Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.

debian
почти 10 лет назад

Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape P ...

github
больше 3 лет назад

Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.

fstec
почти 10 лет назад

Уязвимость браузеров Firefox и Firefox ESR, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

EPSS

Процентиль: 95%
0.18188
Средний

6.8 Medium

CVSS2