Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-5607

Опубликовано: 20 нояб. 2013
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5

Описание

Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefox ESR 17.x before 17.0.11 and 24.x before 24.1.1, and SeaMonkey before 2.22.1, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted X.509 certificate, a related issue to CVE-2013-1741.

РелизСтатусПримечание
devel

not-affected

26.0~b6+build1-0ubuntu1
lucid

ignored

end of life
precise

released

25.0.1+build1-0ubuntu0.12.04.1
quantal

released

25.0.1+build1-0ubuntu0.12.10.1
raring

released

25.0.1+build1-0ubuntu0.13.04.1
saucy

released

25.0.1+build1-0ubuntu0.13.10.1
upstream

released

25.0.1

Показывать по

РелизСтатусПримечание
devel

not-affected

2:4.10.2-1ubuntu1
lucid

released

4.9.5-0ubuntu0.10.04.2
precise

released

4.9.5-0ubuntu0.12.04.2
quantal

released

4.9.5-0ubuntu0.12.10.2
raring

ignored

end of life
saucy

released

2:4.9.5-1ubuntu1.1
upstream

released

4.10.2

Показывать по

РелизСтатусПримечание
devel

released

1:24.1.1+build1-0ubuntu0.13.10.1
lucid

ignored

end of life
precise

released

1:24.1.1+build1-0ubuntu0.12.04.1
quantal

released

1:24.1.1+build1-0ubuntu0.12.10.1
raring

released

1:24.1.1+build1-0ubuntu0.13.04.1
saucy

released

1:24.1.1+build1-0ubuntu0.13.10.1
upstream

released

24.1.1

Показывать по

EPSS

Процентиль: 81%
0.01591
Низкий

7.5 High

CVSS2

Связанные уязвимости

redhat
почти 12 лет назад

Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefox ESR 17.x before 17.0.11 and 24.x before 24.1.1, and SeaMonkey before 2.22.1, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted X.509 certificate, a related issue to CVE-2013-1741.

nvd
почти 12 лет назад

Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefox ESR 17.x before 17.0.11 and 24.x before 24.1.1, and SeaMonkey before 2.22.1, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted X.509 certificate, a related issue to CVE-2013-1741.

debian
почти 12 лет назад

Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape ...

github
больше 3 лет назад

Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefox ESR 17.x before 17.0.11 and 24.x before 24.1.1, and SeaMonkey before 2.22.1, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted X.509 certificate, a related issue to CVE-2013-1741.

oracle-oval
больше 11 лет назад

ELSA-2013-1829: nss, nspr, and nss-util security update (IMPORTANT)

EPSS

Процентиль: 81%
0.01591
Низкий

7.5 High

CVSS2

Уязвимость CVE-2013-5607