CVE-2013-0791
The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other…
Does this matter?
Lower severity and a low EPSS score (5.21%). Track it; it rarely justifies an emergency change on its own.
Description
The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted certificate.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 5.21% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- mozilla/firefox · mozilla/network security services · mozilla/seamonkey · mozilla/thunderbird · mozilla/thunderbird esr · canonical/ubuntu linux · oracle/vm server · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux workstation
- Source
- security@mozilla.org
References
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00009.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00010.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00013.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00019.htmlBroken Link
- http://rhn.redhat.com/errata/RHSA-2013-1135.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1144.htmlThird Party Advisory
- http://www.mozilla.org/security/announce/2013/mfsa2013-40.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlThird Party Advisory
- http://www.securityfocus.com/bid/58826Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1791-1Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=629816Issue Tracking, Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17150Broken Link
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00009.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00010.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00013.htmlBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00019.htmlBroken Link
- http://rhn.redhat.com/errata/RHSA-2013-1135.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1144.htmlThird Party Advisory
- http://www.mozilla.org/security/announce/2013/mfsa2013-40.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlThird Party Advisory
- http://www.securityfocus.com/bid/58826Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1791-1Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=629816Issue Tracking, Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17150Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.