CVE-2014-1545
published 2014-06-11CVE-2014-1545: Mozilla Netscape Portable Runtime (NSPR) before 4.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via…
PriorityP349critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.33%
92.8th percentile
Mozilla Netscape Portable Runtime (NSPR) before 4.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via vectors involving the sprintf and console functions.
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nspr | < nspr 2:4.10.6-1 (bookworm) | nspr 2:4.10.6-1 (bookworm) |
| mozilla | netscape_portable_runtime | <= 4.10.5 | — |
| mozilla | netscape_portable_runtime | — | — |
| mozilla | netscape_portable_runtime | — | — |
| mozilla | netscape_portable_runtime | — | — |
| mozilla | netscape_portable_runtime | — | — |
| mozilla | netscape_portable_runtime | — | — |
| mozilla | netscape_portable_runtime | — | — |
| mozilla | netscape_portable_runtime | — | — |
| mozilla | netscape_portable_runtime | — | — |
| mozilla | netscape_portable_runtime | — | — |
| mozilla | netscape_portable_runtime | — | — |
| mozilla | netscape_portable_runtime | — | — |
| mozilla | netscape_portable_runtime | — | — |
| mozilla | netscape_portable_runtime | — | — |
| mozilla | netscape_portable_runtime | — | — |
| mozilla | netscape_portable_runtime | — | — |
| mozilla | netscape_portable_runtime | — | — |
| mozilla | netscape_portable_runtime | — | — |
| mozilla | netscape_portable_runtime | — | — |
| mozilla | netscape_portable_runtime | — | — |
| mozilla | netscape_portable_runtime | — | — |
| mozilla | netscape_portable_runtime | — | — |
| mozilla | netscape_portable_runtime | — | — |
| mozilla | netscape_portable_runtime | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
NSPR vulnerability
vendor_ubuntu·2014-07-02
CVE-2014-1545 NSPR vulnerability
Title: NSPR vulnerability
Summary: NSPR could be made to crash or run programs if it received specially
crafted input.
Abhishek Arya discovered that NSPR incorrectly handled certain console
functions. A remote attacker could use this issue to cause NSPR to crash,
resulting in a denial of service, or possibly execute arbitrary code. The
default compiler options for affected releases should reduce the
vulnerability to a denial of service.
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Red Hat
Mozilla: Out of bounds write in NSPR (MFSA 2014-55)
vendor_redhat·2014-06-10·CVSS 10.0
CVE-2014-1545 [CRITICAL] CWE-787 Mozilla: Out of bounds write in NSPR (MFSA 2014-55)
Mozilla: Out of bounds write in NSPR (MFSA 2014-55)
Mozilla Netscape Portable Runtime (NSPR) before 4.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via vectors involving the sprintf and console functions.
An out-of-bounds write flaw was found in NSPR. A remote attacker could potentially use this flaw to crash an application using NSPR or, possibly, execute arbitrary code with the privileges of the user running that application. This NSPR flaw was not exposed to web content in any shipped version of Firefox.
Debian
CVE-2014-1545: nspr - Mozilla Netscape Portable Runtime (NSPR) before 4.10.6 allows remote attackers t...
vendor_debian·2014·CVSS 10.0
CVE-2014-1545 [CRITICAL] CVE-2014-1545: nspr - Mozilla Netscape Portable Runtime (NSPR) before 4.10.6 allows remote attackers t...
Mozilla Netscape Portable Runtime (NSPR) before 4.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via vectors involving the sprintf and console functions.
Scope: local
bookworm: resolved (fixed in 2:4.10.6-1)
bullseye: resolved (fixed in 2:4.10.6-1)
forky: resolved (fixed in 2:4.10.6-1)
sid: resolved (fixed in 2:4.10.6-1)
trixie: resolved (fixed in 2:4.10.6-1)
GHSA
GHSA-r364-qw2p-cpfx: Mozilla Netscape Portable Runtime (NSPR) before 4
ghsa_unreviewed·2022-05-14
CVE-2014-1545 [HIGH] GHSA-r364-qw2p-cpfx: Mozilla Netscape Portable Runtime (NSPR) before 4
Mozilla Netscape Portable Runtime (NSPR) before 4.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via vectors involving the sprintf and console functions.
OSV
CVE-2014-1545: Mozilla Netscape Portable Runtime (NSPR) before 4
osv·2014-06-11·CVSS 10.0
CVE-2014-1545 [CRITICAL] CVE-2014-1545: Mozilla Netscape Portable Runtime (NSPR) before 4
Mozilla Netscape Portable Runtime (NSPR) before 4.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via vectors involving the sprintf and console functions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-1545 nspr: Mozilla: Out of bounds write in NSPR (MFSA 2014-55) [fedora-all]
bugzilla·2014-07-03·CVSS 10.0
CVE-2014-1545 [CRITICAL] CVE-2014-1545 nspr: Mozilla: Out of bounds write in NSPR (MFSA 2014-55) [fedora-all]
CVE-2014-1545 nspr: Mozilla: Out of bounds write in NSPR (MFSA 2014-55) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects mu
Bugzilla
CVE-2014-1545 Mozilla: Out of bounds write in NSPR (MFSA 2014-55)
bugzilla·2014-06-10·CVSS 10.0
CVE-2014-1545 [CRITICAL] CVE-2014-1545 Mozilla: Out of bounds write in NSPR (MFSA 2014-55)
CVE-2014-1545 Mozilla: Out of bounds write in NSPR (MFSA 2014-55)
Security researcher Abhishek Arya (Inferno) of the Google Chrome Security Team reported an out of bounds write in the Netscape Portable Runtime (NSPR) leading to a potentially exploitable crash or code execution. This issue is fixed in NSPR version 4.10.6.
This NSPR flaw was not exposed to web content in any shipped version of Firefox.
External Reference:
http://www.mozilla.org/security/announce/2014/mfsa2014-55.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Abhishek Arya as the original reporter.
Discussion:
Created nspr tracking bugs for this issue:
Affects: fedora-all [bug 1115783]
---
This issue has been addressed in following products:
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00023.htmlhttp://lists.opensuse.org/opensuse-updates/2014-06/msg00040.htmlhttp://lists.opensuse.org/opensuse-updates/2014-07/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2014-07/msg00004.htmlhttp://secunia.com/advisories/58984http://secunia.com/advisories/59229http://secunia.com/advisories/59275http://secunia.com/advisories/59318http://secunia.com/advisories/59377http://secunia.com/advisories/59387http://secunia.com/advisories/59425http://secunia.com/advisories/59486http://secunia.com/advisories/59614http://www.debian.org/security/2014/dsa-2955http://www.debian.org/security/2014/dsa-2960http://www.debian.org/security/2014/dsa-2962http://www.mozilla.org/security/announce/2014/mfsa2014-55.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/67975http://www.securitytracker.com/id/1030404http://www.ubuntu.com/usn/USN-2265-1https://bugzilla.mozilla.org/show_bug.cgi?id=1018783https://bugzilla.redhat.com/show_bug.cgi?id=1107432https://security.gentoo.org/glsa/201504-01http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-06/msg00023.htmlhttp://lists.opensuse.org/opensuse-updates/2014-06/msg00040.htmlhttp://lists.opensuse.org/opensuse-updates/2014-07/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2014-07/msg00004.htmlhttp://secunia.com/advisories/58984http://secunia.com/advisories/59229http://secunia.com/advisories/59275http://secunia.com/advisories/59318http://secunia.com/advisories/59377http://secunia.com/advisories/59387http://secunia.com/advisories/59425http://secunia.com/advisories/59486http://secunia.com/advisories/59614http://www.debian.org/security/2014/dsa-2955http://www.debian.org/security/2014/dsa-2960http://www.debian.org/security/2014/dsa-2962http://www.mozilla.org/security/announce/2014/mfsa2014-55.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/67975http://www.securitytracker.com/id/1030404http://www.ubuntu.com/usn/USN-2265-1https://bugzilla.mozilla.org/show_bug.cgi?id=1018783https://bugzilla.redhat.com/show_bug.cgi?id=1107432https://security.gentoo.org/glsa/201504-01
2014-06-11
Published