CVE-2013-5607
published 2013-11-20CVE-2013-5607: Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefox ESR 17.x…
PriorityP431high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.04%
86.0th percentile
Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefox ESR 17.x before 17.0.11 and 24.x before 24.1.1, and SeaMonkey before 2.22.1, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted X.509 certificate, a related issue to CVE-2013-1741.
Affected
105 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nspr | < nspr 2:4.10.2-1 (bookworm) | nspr 2:4.10.2-1 (bookworm) |
| mozilla | firefox | <= 25.0 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3xqp-xvq8-m5hr: Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4
ghsa_unreviewed·2022-05-14·CVSS 7.5
CVE-2013-5607 [HIGH] GHSA-3xqp-xvq8-m5hr: Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4
Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefox ESR 17.x before 17.0.11 and 24.x before 24.1.1, and SeaMonkey before 2.22.1, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted X.509 certificate, a related issue to CVE-2013-1741.
OSV
CVE-2013-5607: Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4
osv·2013-11-20·CVSS 7.5
CVE-2013-5607 [HIGH] CVE-2013-5607: Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4
Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefox ESR 17.x before 17.0.11 and 24.x before 24.1.1, and SeaMonkey before 2.22.1, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted X.509 certificate, a related issue to CVE-2013-1741.
Ubuntu
NSPR vulnerability
vendor_ubuntu·2014-01-23
CVE-2013-5607 NSPR vulnerability
Title: NSPR vulnerability
Summary: NSPR could be made to crash or run programs if it received a specially
crafted certificate.
It was discovered that NSPR incorrectly handled certain malformed X.509
certificates. A remote attacker could use a crafted X.509 certificate to
cause NSPR to crash, leading to a denial of service, or possibly execute
arbitrary code.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2013-11-21·CVSS 7.5
CVE-2013-1741 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into connecting to a malicious server, an attacker could possibly
exploit these to cause a denial of service via application crash,
potentially execute arbitrary code, or lead to information disclosure.
(CVE-2013-1741, CVE-2013-2566, CVE-2013-5605, CVE-2013-5607)
Instructions: After a standard system update you need to restart Thunderbird to make
all the necessary changes.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2013-11-20·CVSS 7.5
CVE-2013-1741 [HIGH] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Several security issues were fixed in Firefox.
Multiple security issues were discovered in Firefox. If a user were tricked
into opening a specially crafted page, an attacker could possibly exploit
these to cause a denial of service via application crash, potentially
execute arbitrary code, or lead to information disclosure. (CVE-2013-1741,
CVE-2013-2566, CVE-2013-5605, CVE-2013-5607)
Instructions: After a standard system update you need to restart Firefox to make
all the necessary changes.
Red Hat
nspr: Avoid unsigned integer wrapping in PL_ArenaAllocate (MFSA 2013-103)
vendor_redhat·2013-11-19·CVSS 7.5
CVE-2013-5607 [HIGH] nspr: Avoid unsigned integer wrapping in PL_ArenaAllocate (MFSA 2013-103)
nspr: Avoid unsigned integer wrapping in PL_ArenaAllocate (MFSA 2013-103)
Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefox ESR 17.x before 17.0.11 and 24.x before 24.1.1, and SeaMonkey before 2.22.1, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted X.509 certificate, a related issue to CVE-2013-1741.
Package: nspr (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-5607: nspr - Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable R...
vendor_debian·2013·CVSS 7.5
CVE-2013-5607 [HIGH] CVE-2013-5607: nspr - Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable R...
Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefox ESR 17.x before 17.0.11 and 24.x before 24.1.1, and SeaMonkey before 2.22.1, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted X.509 certificate, a related issue to CVE-2013-1741.
Scope: local
bookworm: resolved (fixed in 2:4.10.2-1)
bullseye: resolved (fixed in 2:4.10.2-1)
forky: resolved (fixed in 2:4.10.2-1)
sid: resolved (fixed in 2:4.10.2-1)
trixie: resolved (fixed in 2:4.10.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-5607 nspr: Avoid unsigned integer wrapping in PL_ArenaAllocate (MFSA 2013-103) [fedora-all]
bugzilla·2013-11-19·CVSS 7.5
CVE-2013-5607 [HIGH] CVE-2013-5607 nspr: Avoid unsigned integer wrapping in PL_ArenaAllocate (MFSA 2013-103) [fedora-all]
CVE-2013-5607 nspr: Avoid unsigned integer wrapping in PL_ArenaAllocate (MFSA 2013-103) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Plea
Bugzilla
CVE-2013-5607 nspr: Avoid unsigned integer wrapping in PL_ArenaAllocate (MFSA 2013-103)
bugzilla·2013-11-18·CVSS 7.5
CVE-2013-5607 [HIGH] CVE-2013-5607 nspr: Avoid unsigned integer wrapping in PL_ArenaAllocate (MFSA 2013-103)
CVE-2013-5607 nspr: Avoid unsigned integer wrapping in PL_ArenaAllocate (MFSA 2013-103)
Pascal Cuoq, RedHat developer Kamil Dudka, and Google developer Wan-Teh Chang found a flaw similar to CVE-2013-1741 in Netscape Portable Runtime (NSPR) library code suffered the same integer truncation.
Upstream patch:
https://hg.mozilla.org/projects/nspr/rev/4df6bc35be64
External Reference:
http://www.mozilla.org/security/announce/2013/mfsa2013-103.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Pascal Cuoq, Kamil Dudka, and Wan-Teh Chang as the original reporters of this issue.
Discussion:
Created nspr tracking bugs for this issue:
Affects: fedora-all [bug 1031898]
---
Fixed upstream in NSPR 4.10.2:
https://groups.goog
Bugzilla
Avoid unsigned integer wrapping in PL_ArenaAllocate
bugzilla·2013-10-17·CVSS 7.5
[HIGH] Avoid unsigned integer wrapping in PL_ArenaAllocate
Avoid unsigned integer wrapping in PL_ArenaAllocate
Created attachment 818175
Patch
The attached patch for PL_ArenaAllocate ensures that the sums of unsigned integers
don't wrap.
Note that a->base, a->avail, and a->limit are of the PRUword type, an unsigned
integer type large enough to hold a pointer. The patch relies on the invariant
that a->base limit and a->avail limit.
Discussion:
Rating sec-critical because of related bug 925100.
---
Friendly nudge for Rob's review.
---
Created attachment 823689
Patch v2
I found that the first two changes in my patch were proposed by
Kamil Dudka (or Pascal Cuoq?) in bug 770534 one year ago.
This patch now contains only the third change.
---
Comment on attachment 823689
Patch v2
r+ rrelyea
---
Comment on attachment 823689
Patch v2
Patc
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00080.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1791.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1829.htmlhttp://security.gentoo.org/glsa/glsa-201406-19.xmlhttp://www.debian.org/security/2013/dsa-2820http://www.mozilla.org/security/announce/2013/mfsa2013-103.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/63802http://www.ubuntu.com/usn/USN-2031-1http://www.ubuntu.com/usn/USN-2032-1http://www.ubuntu.com/usn/USN-2087-1https://bugzilla.mozilla.org/show_bug.cgi?id=927687https://groups.google.com/forum/message/raw?msg=mozilla.dev.tech.nspr/_8AcygMEjSA/mm_cqQzLPFQJhttps://security.gentoo.org/glsa/201504-01http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00000.htmlhttp://lists.opensuse.org/opensuse-updates/2013-11/msg00080.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1791.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1829.htmlhttp://security.gentoo.org/glsa/glsa-201406-19.xmlhttp://www.debian.org/security/2013/dsa-2820http://www.mozilla.org/security/announce/2013/mfsa2013-103.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/63802http://www.ubuntu.com/usn/USN-2031-1http://www.ubuntu.com/usn/USN-2032-1http://www.ubuntu.com/usn/USN-2087-1https://bugzilla.mozilla.org/show_bug.cgi?id=927687https://groups.google.com/forum/message/raw?msg=mozilla.dev.tech.nspr/_8AcygMEjSA/mm_cqQzLPFQJhttps://security.gentoo.org/glsa/201504-01
2013-11-20
Published