CVE-2013-1739
published 2013-10-22CVE-2013-1739: Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote…
PriorityP425medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.41%
87.6th percentile
Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nss | < nss 2:3.15.2-1 (bookworm) | nss 2:3.15.2-1 (bookworm) |
| mozilla | network_security_services | <= 3.15.1 | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | nss | >= 0 < 2:3.15.2-1 | 2:3.15.2-1 |
| mozilla | nss | >= 0 < 2:3.15.2-1 | 2:3.15.2-1 |
| mozilla | nss | >= 0 < 2:3.15.2-1 | 2:3.15.2-1 |
| mozilla | nss | >= 0 < 2:3.15.2-1 | 2:3.15.2-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
NSS vulnerabilities
vendor_ubuntu·2013-11-18
CVE-2013-1739 NSS vulnerabilities
Title: NSS vulnerabilities
Summary: Several security issues were fixed in NSS.
Multiple security issues were discovered in NSS. If a user were tricked
into connecting to a malicious server, an attacker could possibly exploit
these to cause a denial of service via application crash, potentially
execute arbitrary code, or lead to information disclosure.
This update also adds TLS v1.2 support to Ubuntu 10.04 LTS, Ubuntu 12.04
LTS, Ubuntu 12.10, and Ubuntu 13.04.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use NSS, such as Evolution and Chromium, to make all the necessary
changes.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2013-10-31·CVSS 5.0
CVE-2013-1739 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple memory safety issues were discovered in Thunderbird. If a user
were tricked in to opening a specially crafted message with scripting
enabled, an attacker could possibly exploit these to cause a denial of
service via application crash, or potentially execute arbitrary code with
the privileges of the user invoking Thunderbird. (CVE-2013-1739,
CVE-2013-5590, CVE-2013-5591)
Jordi Chancel discovered that HTML select elements could display arbitrary
content. If a user had scripting enabled, an attacker could potentially
exploit this to conduct URL spoofing or clickjacking attacks.
(CVE-2013-5593)
Abhishek Arya discovered a crash when processing XSLT data in some
circumstances. If a user ha
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-10-29·CVSS 5.0
CVE-2013-1739 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple memory safety issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted page, an attacker could possibly
exploit these to cause a denial of service via application crash, or
potentially execute arbitrary code with the privileges of the user
invoking Firefox. (CVE-2013-1739, CVE-2013-5590, CVE-2013-5591,
CVE-2013-5592)
Jordi Chancel discovered that HTML select elements could display arbitrary
content. An attacker could potentially exploit this to conduct
URL spoofing or clickjacking attacks (CVE-2013-5593)
Abhishek Arya discovered a crash when processing XSLT data in some
circumstances. An attacker could potenti
Red Hat
nss: Avoid uninitialized data read in the event of a decryption failure
vendor_redhat·2013-10-17·CVSS 5.0
CVE-2013-1739 [MEDIUM] nss: Avoid uninitialized data read in the event of a decryption failure
nss: Avoid uninitialized data read in the event of a decryption failure
Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure.
Statement: This issue affects the version of nss as shipped with Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this issue as having moderate security impact, a future update may address this flaw.
Package: nss (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-1739: nss - Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data ...
vendor_debian·2013·CVSS 5.0
CVE-2013-1739 [MEDIUM] CVE-2013-1739: nss - Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data ...
Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure.
Scope: local
bookworm: resolved (fixed in 2:3.15.2-1)
bullseye: resolved (fixed in 2:3.15.2-1)
forky: resolved (fixed in 2:3.15.2-1)
sid: resolved (fixed in 2:3.15.2-1)
trixie: resolved (fixed in 2:3.15.2-1)
GHSA
GHSA-9j62-mm37-x965: Mozilla Network Security Services (NSS) before 3
ghsa_unreviewed·2022-05-14
CVE-2013-1739 [MEDIUM] GHSA-9j62-mm37-x965: Mozilla Network Security Services (NSS) before 3
Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure.
OSV
CVE-2013-1739: Mozilla Network Security Services (NSS) before 3
osv·2013-10-22·CVSS 5.0
CVE-2013-1739 [MEDIUM] CVE-2013-1739: Mozilla Network Security Services (NSS) before 3
Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1739 nss: Avoid uninitialized data read in the event of a decryption failure
bugzilla·2013-09-27·CVSS 4.3
CVE-2013-1739 [MEDIUM] CVE-2013-1739 nss: Avoid uninitialized data read in the event of a decryption failure
CVE-2013-1739 nss: Avoid uninitialized data read in the event of a decryption failure
A flaw was found in the way nss read uninitialized data, when there was a decryption failure. A remote attacker could use this flaw to cause denial of service for applications linked with the nss library (application crash)
The vulnerable code was added in NSS 3.14.3 to fix the lucky-13 issue (CVE-2013-1620). This issue is resolved in nss-3.15.2
References:
https://developer.mozilla.org/en-US/docs/NSS/NSS_3.15.2_release_notes
https://bugzilla.mozilla.org/show_bug.cgi?id=894370 (currently closed)
patch: https://hg.mozilla.org/projects/nss/rev/56436aa3463f
Discussion:
Statement:
This issue affects the version of nss as shipped with Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team h
Bugzilla
Assertion failure: inputLen >= spec->mac_size, at c:/work/mozilla/builds/beta/mozilla/security/nss/lib/ssl/ssl3con.c:2057
bugzilla·2013-07-16
[MEDIUM] Assertion failure: inputLen >= spec->mac_size, at c:/work/mozilla/builds/beta/mozilla/security/nss/lib/ssl/ssl3con.c:2057
Assertion failure: inputLen >= spec->mac_size, at c:/work/mozilla/builds/beta/mozilla/security/nss/lib/ssl/ssl3con.c:2057
Created attachment 776367
stack
Happens in beta and nightly debug builds on all platforms according to bughunter
Assertion failure: inputLen >= spec->mac_size, at c:/work/mozilla/builds/beta/mozilla/security/nss/lib/ssl/ssl3con.c:2057
Will try to generate a testcase
Steps to repoduce is to load https://sc.lcsd.gov.hk/uniS/webcat.hkpl.gov.hk/lib/item;jsessionid=1414DB917107CA0666E4352692442460?id=chamo:3207909&theme=WEB&copies-sort=3%2Basc in a debug build and nearly crash on load
Discussion:
note, there seems to be a problem with this site. While trying to use wget to create the testcase i got:
Connecting to sc.lcsd.gov.hk (sc.lcsd.gov.hk)|202.53.141.71|:443...
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00014.htmlhttp://lists.opensuse.org/opensuse-updates/2013-10/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2013-10/msg00016.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1791.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1829.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://security.gentoo.org/glsa/glsa-201406-19.xmlhttp://www.debian.org/security/2013/dsa-2790http://www.mozilla.org/security/announce/2013/mfsa2013-93.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/62966http://www.ubuntu.com/usn/USN-2030-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=894370https://bugzilla.redhat.com/show_bug.cgi?id=1012656https://developer.mozilla.org/en-US/docs/NSS/NSS_3.15.2_release_noteshttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19254http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00014.htmlhttp://lists.opensuse.org/opensuse-updates/2013-10/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2013-10/msg00016.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1791.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1829.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://security.gentoo.org/glsa/glsa-201406-19.xmlhttp://www.debian.org/security/2013/dsa-2790http://www.mozilla.org/security/announce/2013/mfsa2013-93.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/62966http://www.ubuntu.com/usn/USN-2030-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=894370https://bugzilla.redhat.com/show_bug.cgi?id=1012656https://developer.mozilla.org/en-US/docs/NSS/NSS_3.15.2_release_noteshttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19254
2013-10-22
Published