Описание
Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.
An out-of-bounds write flaw was found in the way NSS performed certain Base64-decoding operations. An attacker could use this flaw to create a specially crafted certificate which, when parsed by NSS, could cause it to crash or execute arbitrary code, using the permissions of the user running an application compiled against the NSS library.
Отчет
The security flaw exists in NSS library Base64 encoder/decoder code. Any application which uses NSS library to parse base64 encoded data could possibly be affected by the flaw. For example:
- Servers compiled against NSS which parse untrusted certificates or any other base64 encoded data from its users.
- Utilities like curl etc which use NSS to parse user provided base64 encoded certificates.
- Applications like Firefox which use NSS to parse client-certificates before passing them to the web server.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 4 | nss | Affected | ||
| Red Hat Enterprise Linux 5.9 Long Life | nss | Fixed | RHSA-2017:1103 | 20.04.2017 |
| Red Hat Enterprise Linux 5 Extended Lifecycle Support | nss | Fixed | RHSA-2017:1101 | 20.04.2017 |
| Red Hat Enterprise Linux 6 | nss | Fixed | RHSA-2017:1100 | 20.04.2017 |
| Red Hat Enterprise Linux 6 | nss-util | Fixed | RHSA-2017:1100 | 20.04.2017 |
| Red Hat Enterprise Linux 6.2 Advanced Update Support | nss-util | Fixed | RHSA-2017:1102 | 20.04.2017 |
| Red Hat Enterprise Linux 6.4 Advanced Update Support | nss-util | Fixed | RHSA-2017:1102 | 20.04.2017 |
| Red Hat Enterprise Linux 6.5 Advanced Update Support | nss-util | Fixed | RHSA-2017:1102 | 20.04.2017 |
| Red Hat Enterprise Linux 6.5 Telco Extended Update Support | nss-util | Fixed | RHSA-2017:1102 | 20.04.2017 |
| Red Hat Enterprise Linux 6.6 Advanced Update Support | nss-util | Fixed | RHSA-2017:1102 | 20.04.2017 |
Показывать по
Дополнительная информация
Статус:
9.8 Critical
CVSS3
Связанные уязвимости
Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.
Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.
Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through ...
Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.
9.8 Critical
CVSS3