CVE-2013-5605
published 2013-11-18CVE-2013-5605: Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.40%
90.3th percentile
Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid handshake packets.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nss | < nss 2:3.15.3-1 (bookworm) | nss 2:3.15.3-1 (bookworm) |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | nss | >= 0 < 2:3.15.3-1 | 2:3.15.3-1 |
| mozilla | nss | >= 0 < 2:3.15.3-1 | 2:3.15.3-1 |
| mozilla | nss | >= 0 < 2:3.15.3-1 | 2:3.15.3-1 |
| mozilla | nss | >= 0 < 2:3.15.3-1 | 2:3.15.3-1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2013-11-21·CVSS 7.5
CVE-2013-1741 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into connecting to a malicious server, an attacker could possibly
exploit these to cause a denial of service via application crash,
potentially execute arbitrary code, or lead to information disclosure.
(CVE-2013-1741, CVE-2013-2566, CVE-2013-5605, CVE-2013-5607)
Instructions: After a standard system update you need to restart Thunderbird to make
all the necessary changes.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-11-20·CVSS 7.5
CVE-2013-1741 [HIGH] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Several security issues were fixed in Firefox.
Multiple security issues were discovered in Firefox. If a user were tricked
into opening a specially crafted page, an attacker could possibly exploit
these to cause a denial of service via application crash, potentially
execute arbitrary code, or lead to information disclosure. (CVE-2013-1741,
CVE-2013-2566, CVE-2013-5605, CVE-2013-5607)
Instructions: After a standard system update you need to restart Firefox to make
all the necessary changes.
Ubuntu
NSS vulnerabilities
vendor_ubuntu·2013-11-18
CVE-2013-1739 NSS vulnerabilities
Title: NSS vulnerabilities
Summary: Several security issues were fixed in NSS.
Multiple security issues were discovered in NSS. If a user were tricked
into connecting to a malicious server, an attacker could possibly exploit
these to cause a denial of service via application crash, potentially
execute arbitrary code, or lead to information disclosure.
This update also adds TLS v1.2 support to Ubuntu 10.04 LTS, Ubuntu 12.04
LTS, Ubuntu 12.10, and Ubuntu 13.04.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use NSS, such as Evolution and Chromium, to make all the necessary
changes.
Red Hat
nss: Null_Cipher() does not respect maxOutputLen (MFSA 2013-103)
vendor_redhat·2013-11-13·CVSS 7.5
CVE-2013-5605 [HIGH] nss: Null_Cipher() does not respect maxOutputLen (MFSA 2013-103)
nss: Null_Cipher() does not respect maxOutputLen (MFSA 2013-103)
Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid handshake packets.
Package: nss (Red Hat Enterprise Linux 7) - Not affected
Package: nss (Red Hat Enterprise Linux Extended Update Support 5.3) - Affected
Debian
CVE-2013-5605: nss - Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15....
vendor_debian·2013·CVSS 7.5
CVE-2013-5605 [HIGH] CVE-2013-5605: nss - Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15....
Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid handshake packets.
Scope: local
bookworm: resolved (fixed in 2:3.15.3-1)
bullseye: resolved (fixed in 2:3.15.3-1)
forky: resolved (fixed in 2:3.15.3-1)
sid: resolved (fixed in 2:3.15.3-1)
trixie: resolved (fixed in 2:3.15.3-1)
GHSA
GHSA-mv87-4w29-5g7x: Mozilla Network Security Services (NSS) 3
ghsa_unreviewed·2022-05-14
CVE-2013-5605 [HIGH] CWE-20 GHSA-mv87-4w29-5g7x: Mozilla Network Security Services (NSS) 3
Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid handshake packets.
OSV
CVE-2013-5605: Mozilla Network Security Services (NSS) 3
osv·2013-11-18·CVSS 7.5
CVE-2013-5605 [HIGH] CVE-2013-5605: Mozilla Network Security Services (NSS) 3
Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid handshake packets.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-5605 CVE-2013-5606 CVE-2013-1741 nss: various flaws [fedora-all]
bugzilla·2013-11-19·CVSS 7.5
CVE-2013-5605 [HIGH] CVE-2013-5605 CVE-2013-5606 CVE-2013-1741 nss: various flaws [fedora-all]
CVE-2013-5605 CVE-2013-5606 CVE-2013-1741 nss: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects
Bugzilla
CVE-2013-5605 nss: Null_Cipher() does not respect maxOutputLen (MFSA 2013-103)
bugzilla·2013-11-15·CVSS 7.5
CVE-2013-5605 [HIGH] CVE-2013-5605 nss: Null_Cipher() does not respect maxOutputLen (MFSA 2013-103)
CVE-2013-5605 nss: Null_Cipher() does not respect maxOutputLen (MFSA 2013-103)
NSS versions 3.14.5 and 3.15.3 were released, documenting the following security fix:
* (CVE-2013-5605) Handle invalid handshake packets
Release notes refer to this currently non-public upstream bug report:
https://bugzilla.mozilla.org/show_bug.cgi?id=934016
Upstream patch:
https://hg.mozilla.org/projects/nss/rev/e79a09364b5e
Release notes:
https://developer.mozilla.org/en-US/docs/NSS/NSS_3.14.5_release_notes
https://developer.mozilla.org/en-US/docs/NSS/NSS_3.15.3_release_notes
Discussion:
Created nss tracking bugs for this issue:
Affects: fedora-all [bug 1031897]
---
Reference:
http://www.mozilla.org/security/announce/2013/mfsa2013-103.html
---
This issue has been addressed in following products:
Bugzilla
Null_Cipher (used during handshake) does not respect maxOutputLen, copying an attacker-supplied # of bytes
bugzilla·2013-11-01
[CRITICAL] Null_Cipher (used during handshake) does not respect maxOutputLen, copying an attacker-supplied # of bytes
Null_Cipher (used during handshake) does not respect maxOutputLen, copying an attacker-supplied # of bytes
The implementation of Null_Cipher uses PORT_Mempcy to copy data from the input buffer to the output buffer, as seen at http://mxr.mozilla.org/nss/source/lib/ssl/ssl3con.c#819
However, it does not validate or cap inputLen to be buf->len - ivLen > (MAX_FRAGMENT_LENGTH + 2048)) {
ssl_ReleaseSpecReadLock(ss);
SSL3_SendAlert(ss, alert_fatal, record_overflow);
PORT_SetError(SSL_ERROR_RX_RECORD_TOO_LONG);
return SECFailure;
}
...
/* decrypt from cText buf to plaintext. */
rv = crSpec->decode(
crSpec->decodeContext, plaintext->buf, (int *)&plaintext->len,
plaintext->space, cText->buf->buf + ivLen, cText->buf->len - ivLen);
...
It seems to me we need to be checking (cText->buf->len - ivL
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00078.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00080.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1791.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1829.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1840.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1841.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0041.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://security.gentoo.org/glsa/glsa-201406-19.xmlhttp://www.debian.org/security/2013/dsa-2800http://www.mozilla.org/security/announce/2013/mfsa2013-103.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/63738http://www.ubuntu.com/usn/USN-2030-1http://www.ubuntu.com/usn/USN-2031-1http://www.ubuntu.com/usn/USN-2032-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=934016https://developer.mozilla.org/docs/NSS/NSS_3.14.5_release_noteshttps://developer.mozilla.org/docs/NSS/NSS_3.15.3_release_noteshttps://security.gentoo.org/glsa/201504-01http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00078.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00080.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1791.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1829.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1840.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1841.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0041.htmlhttp://seclists.org/fulldisclosure/2014/Dec/23http://security.gentoo.org/glsa/glsa-201406-19.xmlhttp://www.debian.org/security/2013/dsa-2800http://www.mozilla.org/security/announce/2013/mfsa2013-103.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/63738http://www.ubuntu.com/usn/USN-2030-1http://www.ubuntu.com/usn/USN-2031-1http://www.ubuntu.com/usn/USN-2032-1http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=934016https://developer.mozilla.org/docs/NSS/NSS_3.14.5_release_noteshttps://developer.mozilla.org/docs/NSS/NSS_3.15.3_release_noteshttps://security.gentoo.org/glsa/201504-01
2013-11-18
Published