CVE-2013-1741
published 2013-11-18CVE-2013-1741: Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have…
PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.89%
89.1th percentile
Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large size value.
Affected
115 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | os_x_yosemite_v10.10.4_and_security_update_2015-005 | — | — |
| debian | nspr | < nspr 2:4.10.2-1 (bookworm) | nspr 2:4.10.2-1 (bookworm) |
| debian | nss | < nss 2:3.15.3-1 (bookworm) | nss 2:3.15.3-1 (bookworm) |
| mozilla | firefox | <= 25.0 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3xqp-xvq8-m5hr: Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2013-5607 [HIGH] GHSA-3xqp-xvq8-m5hr: Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4
Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefox ESR 17.x before 17.0.11 and 24.x before 24.1.1, and SeaMonkey before 2.22.1, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted X.509 certificate, a related issue to CVE-2013-1741.
GHSA
GHSA-9953-888v-2xw2: Integer overflow in Mozilla Network Security Services (NSS) 3
ghsa_unreviewed·2022-05-14
CVE-2013-1741 [HIGH] GHSA-9953-888v-2xw2: Integer overflow in Mozilla Network Security Services (NSS) 3
Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large size value.
OSV
CVE-2013-5607: Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4
osv·2013-11-20·CVSS 7.5
CVE-2013-5607 [HIGH] CVE-2013-5607: Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4
Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefox ESR 17.x before 17.0.11 and 24.x before 24.1.1, and SeaMonkey before 2.22.1, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted X.509 certificate, a related issue to CVE-2013-1741.
OSV
CVE-2013-1741: Integer overflow in Mozilla Network Security Services (NSS) 3
osv·2013-11-18·CVSS 7.5
CVE-2013-1741 [HIGH] CVE-2013-1741: Integer overflow in Mozilla Network Security Services (NSS) 3
Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large size value.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2013-11-21·CVSS 7.5
CVE-2013-1741 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into connecting to a malicious server, an attacker could possibly
exploit these to cause a denial of service via application crash,
potentially execute arbitrary code, or lead to information disclosure.
(CVE-2013-1741, CVE-2013-2566, CVE-2013-5605, CVE-2013-5607)
Instructions: After a standard system update you need to restart Thunderbird to make
all the necessary changes.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-11-20·CVSS 7.5
CVE-2013-1741 [HIGH] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Several security issues were fixed in Firefox.
Multiple security issues were discovered in Firefox. If a user were tricked
into opening a specially crafted page, an attacker could possibly exploit
these to cause a denial of service via application crash, potentially
execute arbitrary code, or lead to information disclosure. (CVE-2013-1741,
CVE-2013-2566, CVE-2013-5605, CVE-2013-5607)
Instructions: After a standard system update you need to restart Firefox to make
all the necessary changes.
Red Hat
nss: Integer truncation in certificate parsing (MFSA 2013-103)
vendor_redhat·2013-11-19·CVSS 7.5
CVE-2013-1741 [HIGH] nss: Integer truncation in certificate parsing (MFSA 2013-103)
nss: Integer truncation in certificate parsing (MFSA 2013-103)
Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large size value.
Package: nss (Red Hat Enterprise Linux 7) - Not affected
Red Hat
nspr: Avoid unsigned integer wrapping in PL_ArenaAllocate (MFSA 2013-103)
vendor_redhat·2013-11-19·CVSS 7.5
CVE-2013-5607 [HIGH] nspr: Avoid unsigned integer wrapping in PL_ArenaAllocate (MFSA 2013-103)
nspr: Avoid unsigned integer wrapping in PL_ArenaAllocate (MFSA 2013-103)
Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefox ESR 17.x before 17.0.11 and 24.x before 24.1.1, and SeaMonkey before 2.22.1, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted X.509 certificate, a related issue to CVE-2013-1741.
Package: nspr (Red Hat Enterprise Linux 7) - Not affected
Ubuntu
NSS vulnerabilities
vendor_ubuntu·2013-11-18
CVE-2013-1739 NSS vulnerabilities
Title: NSS vulnerabilities
Summary: Several security issues were fixed in NSS.
Multiple security issues were discovered in NSS. If a user were tricked
into connecting to a malicious server, an attacker could possibly exploit
these to cause a denial of service via application crash, potentially
execute arbitrary code, or lead to information disclosure.
This update also adds TLS v1.2 support to Ubuntu 10.04 LTS, Ubuntu 12.04
LTS, Ubuntu 12.10, and Ubuntu 13.04.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use NSS, such as Evolution and Chromium, to make all the necessary
changes.
Debian
CVE-2013-1741: nss - Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 a...
vendor_debian·2013·CVSS 7.5
CVE-2013-1741 [HIGH] CVE-2013-1741: nss - Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 a...
Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large size value.
Scope: local
bookworm: resolved (fixed in 2:3.15.3-1)
bullseye: resolved (fixed in 2:3.15.3-1)
forky: resolved (fixed in 2:3.15.3-1)
sid: resolved (fixed in 2:3.15.3-1)
trixie: resolved (fixed in 2:3.15.3-1)
Debian
CVE-2013-5607: nspr - Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable R...
vendor_debian·2013·CVSS 7.5
CVE-2013-5607 [HIGH] CVE-2013-5607: nspr - Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable R...
Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefox ESR 17.x before 17.0.11 and 24.x before 24.1.1, and SeaMonkey before 2.22.1, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted X.509 certificate, a related issue to CVE-2013-1741.
Scope: local
bookworm: resolved (fixed in 2:4.10.2-1)
bullseye: resolved (fixed in 2:4.10.2-1)
forky: resolved (fixed in 2:4.10.2-1)
sid: resolved (fixed in 2:4.10.2-1)
trixie: resolved (fixed in 2:4.10.2-1)
Apple
CVE-2013-1741: iOS 8.4
vendor_apple·CVSS 7.5
CVE-2013-1741 [HIGH] CVE-2013-1741: iOS 8.4
Apple Security Update: About the security content of iOS 8.4
Product: iOS
Version: 8.4
CVE: CVE-2013-1741
Component: CVE-2013-1741
Apple
CVE-2013-1741: OS X Yosemite v10.10.4 and Security Update 2015-005
vendor_apple·CVSS 7.5
CVE-2013-1741 [HIGH] CVE-2013-1741: OS X Yosemite v10.10.4 and Security Update 2015-005
Apple Security Update: About the security content of OS X Yosemite v10.10.4 and Security Update 2015-005
Product: OS X Yosemite v10.10.4 and Security Update 2015-005
CVE: CVE-2013-1741
Component: CVE-2013-1741
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-5605 CVE-2013-5606 CVE-2013-1741 nss: various flaws [fedora-all]
bugzilla·2013-11-19·CVSS 7.5
CVE-2013-5605 [HIGH] CVE-2013-5605 CVE-2013-5606 CVE-2013-1741 nss: various flaws [fedora-all]
CVE-2013-5605 CVE-2013-5606 CVE-2013-1741 nss: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects
Bugzilla
CVE-2013-1741 nss: Integer truncation in certificate parsing (MFSA 2013-103)
bugzilla·2013-11-18·CVSS 7.5
CVE-2013-1741 [HIGH] CVE-2013-1741 nss: Integer truncation in certificate parsing (MFSA 2013-103)
CVE-2013-1741 nss: Integer truncation in certificate parsing (MFSA 2013-103)
Google security researcher Tavis Ormandy reported a runaway memset in certificate parsing on 64-bit computers leading to a crash by attempting to write 4Gb of nulls.
Upstream patch:
https://hg.mozilla.org/projects/nss/rev/612d7d1eb9e7
Release notes:
https://developer.mozilla.org/en-US/docs/NSS/NSS_3.15.3_release_notes
External Reference:
http://www.mozilla.org/security/announce/2013/mfsa2013-103.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Tavis Ormandy as the original reporter of this issue.
Discussion:
Created nss tracking bugs for this issue:
Affects: fedora-all [bug 1031897]
---
This issue has been addressed in following pr
Bugzilla
CVE-2013-5607 nspr: Avoid unsigned integer wrapping in PL_ArenaAllocate (MFSA 2013-103)
bugzilla·2013-11-18·CVSS 7.5
CVE-2013-5607 [HIGH] CVE-2013-5607 nspr: Avoid unsigned integer wrapping in PL_ArenaAllocate (MFSA 2013-103)
CVE-2013-5607 nspr: Avoid unsigned integer wrapping in PL_ArenaAllocate (MFSA 2013-103)
Pascal Cuoq, RedHat developer Kamil Dudka, and Google developer Wan-Teh Chang found a flaw similar to CVE-2013-1741 in Netscape Portable Runtime (NSPR) library code suffered the same integer truncation.
Upstream patch:
https://hg.mozilla.org/projects/nspr/rev/4df6bc35be64
External Reference:
http://www.mozilla.org/security/announce/2013/mfsa2013-103.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Pascal Cuoq, Kamil Dudka, and Wan-Teh Chang as the original reporters of this issue.
Discussion:
Created nspr tracking bugs for this issue:
Affects: fedora-all [bug 1031898]
---
Fixed upstream in NSPR 4.10.2:
https://groups.goog
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761http://lists.apple.com/archives/security-announce/2015/Jun/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-12/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00080.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1791.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1829.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://security.gentoo.org/glsa/glsa-201406-19.xmlhttp://support.apple.com/kb/HT204941http://support.apple.com/kb/HT204942http://www.debian.org/security/2014/dsa-2994http://www.mozilla.org/security/announce/2013/mfsa2013-103.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/63736http://www.ubuntu.com/usn/USN-2030-1http://www.ubuntu.com/usn/USN-2031-1http://www.ubuntu.com/usn/USN-2032-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=925100https://developer.mozilla.org/docs/NSS/NSS_3.15.3_release_noteshttps://security.gentoo.org/glsa/201504-01http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761http://lists.apple.com/archives/security-announce/2015/Jun/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-12/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00080.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1791.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1829.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://security.gentoo.org/glsa/glsa-201406-19.xmlhttp://support.apple.com/kb/HT204941http://support.apple.com/kb/HT204942http://www.debian.org/security/2014/dsa-2994http://www.mozilla.org/security/announce/2013/mfsa2013-103.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/63736http://www.ubuntu.com/usn/USN-2030-1http://www.ubuntu.com/usn/USN-2031-1http://www.ubuntu.com/usn/USN-2032-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=925100https://developer.mozilla.org/docs/NSS/NSS_3.15.3_release_noteshttps://security.gentoo.org/glsa/201504-01
2013-11-18
Published