CVE-2012-0441
published 2012-06-05CVE-2012-0441: The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (NSS) before 3.13.4, as used in Firefox 4.x through 12.0, Firefox ESR 10.x…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.94%
85.6th percentile
The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (NSS) before 3.13.4, as used in Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10, allows remote attackers to cause a denial of service (application crash) via a zero-length item, as demonstrated by (1) a zero-length basic constraint or (2) a zero-length field in an OCSP response.
Affected
140 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nss | < nss 3.13.4-1 (bookworm) | nss 3.13.4-1 (bookworm) |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | network_security_services | <= 3.12.3 | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_ubuntu10.0CRITICAL
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware security updates for vSphere API and ESX Service Console
vendor_vmware·2012-11-15·CVSS 5.0
CVE-2011-4940 [MEDIUM] VMware security updates for vSphere API and ESX Service Console
VMSA-2012-0016: VMware security updates for vSphere API and ESX Service Console
a. VMware vSphere API denial of service vulnerability The VMware vSphere API contains a denial of service vulnerability. This issue allows an unauthenticated user to send a maliciously crafted API request and disable the host daemon. Exploitation of the issue would prevent management activities on the host but any virtual machines running on the host would be unaffected. VMware would like to thank Sebastián Tello of Core Security Technologies for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2012-5703 to this issue. Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is a
Ubuntu
NSS vulnerability
vendor_ubuntu·2012-08-21
CVE-2012-0441 NSS vulnerability
Title: NSS vulnerability
Summary: NSS could be made to crash if it opened a specially crafted certificate.
USN-1540-1 fixed vulnerabilities in NSS. This update provides the
corresponding updates for Ubuntu 12.04 LTS.
Original advisory details:
Kaspar Brand discovered a vulnerability in how the Network Security
Services (NSS) ASN.1 decoder handles zero length items. If the user were
tricked into opening a specially crafted certificate, an attacker could
possibly exploit this to cause a denial of service via application crash.
Instructions: After a standard system update you need to restart any applications that
use NSS, such as Evolution, to make all the necessary changes.
Ubuntu
NSS vulnerability
vendor_ubuntu·2012-08-16
CVE-2012-0441 NSS vulnerability
Title: NSS vulnerability
Summary: NSS could be made to crash if it opened a specially crafted certificate.
Kaspar Brand discovered a vulnerability in how the Network Security
Services (NSS) ASN.1 decoder handles zero length items. If the user were
tricked into opening a specially crafted certificate, an attacker could
possibly exploit this to cause a denial of service via application crash.
Instructions: After a standard system update you need to restart any applications that
use NSS, such as Evolution, to make all the necessary changes.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2012-06-27·CVSS 10.0
CVE-2011-3101 [CRITICAL] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
USN-1463-1 fixed vulnerabilities in Firefox. This update provides the
corresponding fixes for Thunderbird.
Original advisory details:
Jesse Ruderman, Igor Bukanov, Bill McCloskey, Christian Holler, Andrew
McCreight, Olli Pettay, Boris Zbarsky, and Brian Bondy discovered memory
safety issues affecting Firefox. If the user were tricked into opening a
specially crafted page, an attacker could possibly exploit these to cause a
denial of service via application crash, or potentially execute code with
the privileges of the user invoking Firefox. (CVE-2012-1937, CVE-2012-1938)
It was discovered that Mozilla's WebGL implementation exposed a bug in
certain NVIDIA graphics drivers. The impact of this
Ubuntu
Firefox regressions
vendor_ubuntu·2012-06-20·CVSS 10.0
[CRITICAL] Firefox regressions
Title: Firefox regressions
Summary: USN-1463-1 introduced regressions in Firefox.
USN-1463-1 fixed vulnerabilities in Firefox. The new package caused a
regression in the rendering of Hebrew text and the ability of the Hotmail
inbox to auto-update. This update fixes the problem.
Original advisory details:
Jesse Ruderman, Igor Bukanov, Bill McCloskey, Christian Holler, Andrew
McCreight, Olli Pettay, Boris Zbarsky, and Brian Bondy discovered memory
safety issues affecting Firefox. If the user were tricked into opening a
specially crafted page, an attacker could possibly exploit these to cause a
denial of service via application crash, or potentially execute code with
the privileges of the user invoking Firefox. (CVE-2012-1937, CVE-2012-1938)
It was discovered that Mozilla's WebGL impleme
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2012-06-06·CVSS 10.0
CVE-2012-1937 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Several security issues were fixed in Firefox.
Jesse Ruderman, Igor Bukanov, Bill McCloskey, Christian Holler, Andrew
McCreight, Olli Pettay, Boris Zbarsky, and Brian Bondy discovered memory
safety issues affecting Firefox. If the user were tricked into opening a
specially crafted page, an attacker could possibly exploit these to cause a
denial of service via application crash, or potentially execute code with
the privileges of the user invoking Firefox. (CVE-2012-1937, CVE-2012-1938)
It was discovered that Mozilla's WebGL implementation exposed a bug in
certain NVIDIA graphics drivers. The impact of this issue has not been
disclosed at this time. (CVE-2011-3101)
Adam Barth discovered that certain inline event handlers were not being
blocked prop
Red Hat
nss: NSS parsing errors with zero length items
vendor_redhat·2012-06-05·CVSS 5.0
CVE-2012-0441 [MEDIUM] nss: NSS parsing errors with zero length items
nss: NSS parsing errors with zero length items
The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (NSS) before 3.13.4, as used in Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10, allows remote attackers to cause a denial of service (application crash) via a zero-length item, as demonstrated by (1) a zero-length basic constraint or (2) a zero-length field in an OCSP response.
Debian
CVE-2012-0441: nss - The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (...
vendor_debian·2012·CVSS 5.0
CVE-2012-0441 [MEDIUM] CVE-2012-0441: nss - The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (...
The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (NSS) before 3.13.4, as used in Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10, allows remote attackers to cause a denial of service (application crash) via a zero-length item, as demonstrated by (1) a zero-length basic constraint or (2) a zero-length field in an OCSP response.
Scope: local
bookworm: resolved (fixed in 3.13.4-1)
bullseye: resolved (fixed in 3.13.4-1)
forky: resolved (fixed in 3.13.4-1)
sid: resolved (fixed in 3.13.4-1)
trixie: resolved (fixed in 3.13.4-1)
GHSA
GHSA-89qc-hqm7-mh22: The ASN
ghsa_unreviewed·2022-05-04
CVE-2012-0441 [MEDIUM] CWE-119 GHSA-89qc-hqm7-mh22: The ASN
The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (NSS) before 3.13.4, as used in Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10, allows remote attackers to cause a denial of service (application crash) via a zero-length item, as demonstrated by (1) a zero-length basic constraint or (2) a zero-length field in an OCSP response.
OSV
CVE-2012-0441: The ASN
osv·2012-06-05·CVSS 5.0
CVE-2012-0441 [MEDIUM] CVE-2012-0441: The ASN
The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (NSS) before 3.13.4, as used in Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10, allows remote attackers to cause a denial of service (application crash) via a zero-length item, as demonstrated by (1) a zero-length basic constraint or (2) a zero-length field in an OCSP response.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-06/msg00015.htmlhttp://secunia.com/advisories/49976http://secunia.com/advisories/50316http://www.debian.org/security/2012/dsa-2490http://www.mandriva.com/security/advisories?name=MDVSA-2012:088http://www.mozilla.org/security/announce/2012/mfsa2012-39.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/53798http://www.ubuntu.com/usn/USN-1540-1http://www.ubuntu.com/usn/USN-1540-2https://bugzilla.mozilla.org/show_bug.cgi?id=715073https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16701http://lists.opensuse.org/opensuse-security-announce/2012-06/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-06/msg00015.htmlhttp://secunia.com/advisories/49976http://secunia.com/advisories/50316http://www.debian.org/security/2012/dsa-2490http://www.mandriva.com/security/advisories?name=MDVSA-2012:088http://www.mozilla.org/security/announce/2012/mfsa2012-39.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/53798http://www.ubuntu.com/usn/USN-1540-1http://www.ubuntu.com/usn/USN-1540-2https://bugzilla.mozilla.org/show_bug.cgi?id=715073https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16701
2012-06-05
Published