CVE-2013-0791
Last modified
CVE-2013-0791 is a vulnerability of currently unknown severity. The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted certificate.. EPSS estimates a 5.21% chance of exploitation in the next 30 days.
Description
The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted certificate.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | <= 20.0 |
| Mozilla | Firefox | >= 17.0, < 17.0.5 |
| Mozilla | Network Security Services | < 3.15 |
| Mozilla | Seamonkey | < 2.17 |
| Mozilla | Thunderbird | < 17.0.5 |
| Mozilla | Thunderbird Esr | >= 17.0, < 17.0.5 |
| Canonical | Ubuntu Linux | 10.04 |
| Canonical | Ubuntu Linux | 11.10 |
| Canonical | Ubuntu Linux | 12.04 |
| Canonical | Ubuntu Linux | 12.10 |
| Oracle | Vm Server | 3.2 |
| Redhat | Enterprise Linux Desktop | 5.0 |
| Redhat | Enterprise Linux Desktop | 6.0 |
| Redhat | Enterprise Linux Eus | 5.9 |
| Redhat | Enterprise Linux Server | 5.0 |
| Redhat | Enterprise Linux Server | 6.0 |
| Redhat | Enterprise Linux Server Aus | 5.9 |
| Redhat | Enterprise Linux Workstation | 5.0 |
| Redhat | Enterprise Linux Workstation | 6.0 |
References
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1135.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1144.htmlThird Party Advisory
- http://www.securityfocus.com/bid/58826Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1791-1Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=629816Issue Tracking, Patch, Vendor Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1135.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1144.htmlThird Party Advisory
- http://www.securityfocus.com/bid/58826Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1791-1Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=629816Issue Tracking, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-0791?
How severe is CVE-2013-0791?
How do I fix CVE-2013-0791?
Are you affected by CVE-2013-0791?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
