CVE-2007-0009
Last modified
CVE-2007-0009 is a vulnerability of currently unknown severity. Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Master Key" length values.. EPSS estimates a 50.36% chance of exploitation in the next 30 days.
Description
Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Master Key" length values.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | >= 1.5, < 1.5.0.10 |
| Mozilla | Firefox | >= 2.0, < 2.0.0.2 |
| Mozilla | Network Security Services | < 3.11.5 |
| Mozilla | Seamonkey | < 1.0.8 |
| Mozilla | Thunderbird | < 1.5.0.10 |
| Debian | Debian Linux | 3.1 |
| Debian | Debian Linux | 4.0 |
| Canonical | Ubuntu Linux | 5.10 |
| Canonical | Ubuntu Linux | 6.06 |
| Canonical | Ubuntu Linux | 6.10 |
References
- http://fedoranews.org/cms/node/2709Broken Link
- http://fedoranews.org/cms/node/2711Broken Link
- http://fedoranews.org/cms/node/2747Broken Link
- http://fedoranews.org/cms/node/2749Broken Link
- http://rhn.redhat.com/errata/RHSA-2007-0077.htmlThird Party Advisory
- http://secunia.com/advisories/24253Third Party Advisory
- http://secunia.com/advisories/24277Third Party Advisory
- http://secunia.com/advisories/24287Third Party Advisory
- http://secunia.com/advisories/24290Third Party Advisory
- http://secunia.com/advisories/24293Third Party Advisory
- http://secunia.com/advisories/24333Third Party Advisory
- http://secunia.com/advisories/24342Third Party Advisory
- http://secunia.com/advisories/24343Third Party Advisory
- http://secunia.com/advisories/24384Third Party Advisory
- http://secunia.com/advisories/24389Third Party Advisory
- http://secunia.com/advisories/24395Third Party Advisory
- http://secunia.com/advisories/24406Third Party Advisory
- http://secunia.com/advisories/24410Third Party Advisory
- http://secunia.com/advisories/24455Third Party Advisory
- http://secunia.com/advisories/24456Third Party Advisory
- http://secunia.com/advisories/24457Third Party Advisory
- http://secunia.com/advisories/24522Third Party Advisory
- http://secunia.com/advisories/24562Third Party Advisory
- http://secunia.com/advisories/24650Third Party Advisory
- http://secunia.com/advisories/24703Third Party Advisory
- http://secunia.com/advisories/25588Third Party Advisory
- http://secunia.com/advisories/25597Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200703-18.xmlThird Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131Mailing List, Third Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.363947Mailing List, Third Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.374851Mailing List, Third Party Advisory
- http://www.debian.org/security/2007/dsa-1336Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200703-22.xmlThird Party Advisory
- http://www.kb.cert.org/vuls/id/592796Third Party Advisory, US Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:050Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:052Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.htmlThird Party Advisory
- http://www.osvdb.org/32106Broken Link
- http://www.redhat.com/support/errata/RHSA-2007-0078.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0079.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0097.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0108.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/461336/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/461809/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/64758Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1017696Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-428-1Third Party Advisory
- http://www.ubuntu.com/usn/usn-431-1Third Party Advisory
- http://www.vupen.com/english/advisories/2007/0718Third Party Advisory
- http://www.vupen.com/english/advisories/2007/0719Third Party Advisory
- http://www.vupen.com/english/advisories/2007/1165Third Party Advisory
- http://www.vupen.com/english/advisories/2007/2141Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=364323Issue Tracking, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32663Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-1081Broken Link
- https://issues.rpath.com/browse/RPL-1103Broken Link
- http://fedoranews.org/cms/node/2709Broken Link
- http://fedoranews.org/cms/node/2711Broken Link
- http://fedoranews.org/cms/node/2747Broken Link
- http://fedoranews.org/cms/node/2749Broken Link
- http://rhn.redhat.com/errata/RHSA-2007-0077.htmlThird Party Advisory
- http://secunia.com/advisories/24253Third Party Advisory
- http://secunia.com/advisories/24277Third Party Advisory
- http://secunia.com/advisories/24287Third Party Advisory
- http://secunia.com/advisories/24290Third Party Advisory
- http://secunia.com/advisories/24293Third Party Advisory
- http://secunia.com/advisories/24333Third Party Advisory
- http://secunia.com/advisories/24342Third Party Advisory
- http://secunia.com/advisories/24343Third Party Advisory
- http://secunia.com/advisories/24384Third Party Advisory
- http://secunia.com/advisories/24389Third Party Advisory
- http://secunia.com/advisories/24395Third Party Advisory
- http://secunia.com/advisories/24406Third Party Advisory
- http://secunia.com/advisories/24410Third Party Advisory
- http://secunia.com/advisories/24455Third Party Advisory
- http://secunia.com/advisories/24456Third Party Advisory
- http://secunia.com/advisories/24457Third Party Advisory
- http://secunia.com/advisories/24522Third Party Advisory
- http://secunia.com/advisories/24562Third Party Advisory
- http://secunia.com/advisories/24650Third Party Advisory
- http://secunia.com/advisories/24703Third Party Advisory
- http://secunia.com/advisories/25588Third Party Advisory
- http://secunia.com/advisories/25597Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200703-18.xmlThird Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131Mailing List, Third Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.363947Mailing List, Third Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.374851Mailing List, Third Party Advisory
- http://www.debian.org/security/2007/dsa-1336Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200703-22.xmlThird Party Advisory
- http://www.kb.cert.org/vuls/id/592796Third Party Advisory, US Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:050Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:052Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.htmlThird Party Advisory
- http://www.osvdb.org/32106Broken Link
- http://www.redhat.com/support/errata/RHSA-2007-0078.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0079.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0097.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0108.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/461336/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/461809/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/64758Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1017696Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-428-1Third Party Advisory
- http://www.ubuntu.com/usn/usn-431-1Third Party Advisory
- http://www.vupen.com/english/advisories/2007/0718Third Party Advisory
- http://www.vupen.com/english/advisories/2007/0719Third Party Advisory
- http://www.vupen.com/english/advisories/2007/1165Third Party Advisory
- http://www.vupen.com/english/advisories/2007/2141Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=364323Issue Tracking, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32663Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-1081Broken Link
- https://issues.rpath.com/browse/RPL-1103Broken Link
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-0009?
How severe is CVE-2007-0009?
How do I fix CVE-2007-0009?
Are you affected by CVE-2007-0009?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
