Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00027.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00029.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00031.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00050.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00068.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00093.html
http://rhn.redhat.com/errata/RHSA-2016-0591.html
http://rhn.redhat.com/errata/RHSA-2016-0684.html
http://rhn.redhat.com/errata/RHSA-2016-0685.html
http://www.debian.org/security/2016/dsa-3576
http://www.debian.org/security/2016/dsa-3688
http://www.mozilla.org/security/announce/2016/mfsa2016-36.html
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
http://www.securityfocus.com/bid/84221
http://www.securitytracker.com/id/1035215
http://www.ubuntu.com/usn/USN-2973-1
https://bto.bluecoat.com/security-advisory/sa124
https://bugzilla.mozilla.org/show_bug.cgi?id=1185033
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.21.1_release_notes
Source: MITRE
Published: 2016-03-13
Updated: 2017-11-04
Type: NVD-CWE-Other
Base Score: 6.8
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
Impact Score: 6.4
Exploitability Score: 8.6
Severity: MEDIUM
Base Score: 8.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 2.8
Severity: HIGH
AND
OR
OR
ID | Name | Product | Family | Severity |
---|---|---|---|---|
99780 | EulerOS 2.0 SP1 : nss, nspr, nss-softokn, nss-util (EulerOS-SA-2016-1017) | Nessus | Huawei Local Security Checks | high |
93871 | Debian DSA-3688-1 : nss - security update (Logjam) (SLOTH) | Nessus | Debian Local Security Checks | high |
802023 | Firefox < 45 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | critical |
93257 | F5 Networks BIG-IP : Mozilla NSS vulnerability (K20145801) | Nessus | F5 Networks Local Security Checks | medium |
91379 | GLSA-201605-06 : Mozilla Products: Multiple vulnerabilities (Logjam) (SLOTH) | Nessus | Gentoo Local Security Checks | critical |
91258 | Ubuntu 12.04 LTS / 14.04 LTS / 15.10 / 16.04 LTS : thunderbird vulnerabilities (USN-2973-1) | Nessus | Ubuntu Local Security Checks | critical |
91242 | Debian DLA-480-1 : nss security update | Nessus | Debian Local Security Checks | high |
91240 | Amazon Linux AMI : nspr / nss-util,nss,nss-softokn (ALAS-2016-702) | Nessus | Amazon Linux Local Security Checks | high |
91138 | Debian DSA-3576-1 : icedove - security update | Nessus | Debian Local Security Checks | critical |
91134 | Debian DLA-472-2 : icedove regression update | Nessus | Debian Local Security Checks | critical |
90752 | Scientific Linux Security Update : nss and nspr on SL5.x i386/x86_64 (20160425) | Nessus | Scientific Linux Local Security Checks | high |
90751 | Scientific Linux Security Update : nss, nspr, nss-softokn, and nss-util on SL7.x x86_64 (20160425) | Nessus | Scientific Linux Local Security Checks | high |
90749 | RHEL 7 : nss, nspr, nss-softokn, and nss-util (RHSA-2016:0685) | Nessus | Red Hat Local Security Checks | high |
90748 | RHEL 5 : nss and nspr (RHSA-2016:0684) | Nessus | Red Hat Local Security Checks | high |
90746 | Oracle Linux 7 : nspr / nss / nss-softokn / nss-util (ELSA-2016-0685) | Nessus | Oracle Linux Local Security Checks | high |
90745 | Oracle Linux 5 : nspr / nss (ELSA-2016-0684) | Nessus | Oracle Linux Local Security Checks | high |
90722 | CentOS 7 : nspr / nss / nss-softokn / nss-util (CESA-2016:0685) | Nessus | CentOS Local Security Checks | high |
90721 | CentOS 5 : nspr / nss (CESA-2016:0684) | Nessus | CentOS Local Security Checks | high |
9207 | Mozilla Firefox < 45.0 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | high |
90392 | Scientific Linux Security Update : nss, nss-util, and nspr on SL6.x i386/x86_64 (20160405) | Nessus | Scientific Linux Local Security Checks | high |
90386 | RHEL 6 : nss, nss-util, and nspr (RHSA-2016:0591) | Nessus | Red Hat Local Security Checks | high |
90383 | Oracle Linux 6 : nspr / nss / nss-util (ELSA-2016-0591) | Nessus | Oracle Linux Local Security Checks | high |
90367 | CentOS 6 : nspr / nss / nss-util (CESA-2016:0591) | Nessus | CentOS Local Security Checks | high |
90263 | SUSE SLES11 Security Update : MozillaFirefox, mozilla-nspr, mozilla-nss (SUSE-SU-2016:0909-1) | Nessus | SuSE Local Security Checks | critical |
90065 | SUSE SLES10 Security Update : MozillaFirefox (SUSE-SU-2016:0820-1) | Nessus | SuSE Local Security Checks | critical |
89990 | SUSE SLED11 / SLES11 Security Update : MozillaFirefox, mozilla-nspr, mozilla-nss (SUSE-SU-2016:0777-1) | Nessus | SuSE Local Security Checks | critical |
89929 | SUSE SLED12 / SLES12 Security Update : MozillaFirefox, mozilla-nspr, mozilla-nss (SUSE-SU-2016:0727-1) | Nessus | SuSE Local Security Checks | critical |
89915 | openSUSE Security Update : Firefox (openSUSE-2016-334) | Nessus | SuSE Local Security Checks | critical |
89913 | openSUSE Security Update : MozillaFirefox / mozilla-nspr / mozilla-nss (openSUSE-2016-332) | Nessus | SuSE Local Security Checks | critical |
89875 | Firefox < 45 Multiple Vulnerabilities | Nessus | Windows | critical |
89873 | Firefox < 45 Multiple Vulnerabilities (Mac OS X) | Nessus | MacOS X Local Security Checks | critical |
89768 | FreeBSD : NSS -- multiple vulnerabilities (c4292768-5273-4f17-a267-c5fe35125ce4) | Nessus | FreeBSD Local Security Checks | medium |