CVE-2015-7181
published 2015-11-05CVE-2015-7181: The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and…
PriorityP342high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
7.51%
93.8th percentile
The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, improperly restricts access to an unspecified data structure, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data, related to a "use-after-poison" issue.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nss | < nss 2:3.20.1-1 (bookworm) | nss 2:3.20.1-1 (bookworm) |
| mozilla | firefox | <= 41.0.2 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 42.0+build2-0ubuntu0.14.04.1 | 42.0+build2-0ubuntu0.14.04.1 |
| mozilla | network_security_services | <= 3.19.2.0 | — |
| mozilla | network_security_services | — | — |
| mozilla | nss | >= 0 < 2:3.20.1-1 | 2:3.20.1-1 |
| mozilla | nss | >= 0 < 2:3.20.1-1 | 2:3.20.1-1 |
| mozilla | nss | >= 0 < 2:3.20.1-1 | 2:3.20.1-1 |
| mozilla | nss | >= 0 < 2:3.20.1-1 | 2:3.20.1-1 |
| mozilla | thunderbird | >= 0 < 1:38.4.0+build3-0ubuntu0.14.04.1 | 1:38.4.0+build3-0ubuntu0.14.04.1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2015-12-01·CVSS 7.5
CVE-2015-4513 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Christian Holler, David Major, Jesse Ruderman, Tyson Smith, Boris Zbarsky,
Randell Jesup, Olli Pettay, Karl Tomlinson, Jeff Walden, and Gary Kwong
discovered multiple memory safety issues in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2015-4513)
Tyson Smith and David Keeler discovered a use-after-poison and buffer
overflow in NSS. An attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user
Ubuntu
NSS vulnerabilities
vendor_ubuntu·2015-11-04
CVE-2015-7181 NSS vulnerabilities
Title: NSS vulnerabilities
Summary: NSS could be made to crash or run programs if it received specially
crafted input.
Tyson Smith and David Keeler discovered that NSS incorrectly handled
decoding certain ASN.1 data. An remote attacker could use this issue to
cause NSS to crash, resulting in a denial of service, or possibly execute
arbitrary code.
Instructions: After a standard system update you need to restart any applications that
use NSS, such as Evolution and Chromium, to make all the necessary changes.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2015-11-04·CVSS 7.5
CVE-2015-4513 [HIGH] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Christian Holler, David Major, Jesse Ruderman, Tyson Smith, Boris Zbarsky,
Randell Jesup, Olli Pettay, Karl Tomlinson, Jeff Walden, Gary Kwong,
Andrew McCreight, Georg Fritzsche, and Carsten Book discovered multiple
memory safety issues in Firefox. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit these to
cause a denial of service via application crash, or execute arbitrary
code with the privileges of the user invoking Firefox. (CVE-2015-4513,
CVE-2015-4514)
Tim Brown discovered that Firefox discloses the hostname during NTLM
authentication in some circumstances. If a user were tricked in to
opening
Red Hat
nss: use-after-poison in sec_asn1d_parse_leaf() (MFSA 2015-133)
vendor_redhat·2015-11-03·CVSS 7.5
CVE-2015-7181 [HIGH] nss: use-after-poison in sec_asn1d_parse_leaf() (MFSA 2015-133)
nss: use-after-poison in sec_asn1d_parse_leaf() (MFSA 2015-133)
The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, improperly restricts access to an unspecified data structure, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data, related to a "use-after-poison" issue.
A use-after-poison flaw was found in the way NSS parsed certain ASN.1 structures. An attacker could use this flaw to cause NSS to crash or execute arbitrary code with the permissions of the user running an application compiled against the NSS library.
Package: nss (Red Hat Enterprise
Debian
CVE-2015-7181: nss - The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) bef...
vendor_debian·2015·CVSS 7.5
CVE-2015-7181 [HIGH] CVE-2015-7181: nss - The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) bef...
The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, improperly restricts access to an unspecified data structure, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data, related to a "use-after-poison" issue.
Scope: local
bookworm: resolved (fixed in 2:3.20.1-1)
bullseye: resolved (fixed in 2:3.20.1-1)
forky: resolved (fixed in 2:3.20.1-1)
sid: resolved (fixed in 2:3.20.1-1)
trixie: resolved (fixed in 2:3.20.1-1)
GHSA
GHSA-738m-rm9h-8qh7: The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3
ghsa_unreviewed·2022-05-17
CVE-2015-7181 [HIGH] CWE-119 GHSA-738m-rm9h-8qh7: The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3
The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, improperly restricts access to an unspecified data structure, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data, related to a "use-after-poison" issue.
OSV
thunderbird vulnerabilities
osv·2015-12-01·CVSS 7.5
CVE-2015-4513 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
Christian Holler, David Major, Jesse Ruderman, Tyson Smith, Boris Zbarsky,
Randell Jesup, Olli Pettay, Karl Tomlinson, Jeff Walden, and Gary Kwong
discovered multiple memory safety issues in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2015-4513)
Tyson Smith and David Keeler discovered a use-after-poison and buffer
overflow in NSS. An attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking Thunderbird. (CVE-2015-7181,
CVE-2015-7182)
Ryan Sleevi d
OSV
CVE-2015-7181: The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3
osv·2015-11-05·CVSS 7.5
CVE-2015-7181 [HIGH] CVE-2015-7181: The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3
The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, improperly restricts access to an unspecified data structure, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data, related to a "use-after-poison" issue.
OSV
firefox vulnerabilities
osv·2015-11-04·CVSS 7.5
[HIGH] firefox vulnerabilities
firefox vulnerabilities
Christian Holler, David Major, Jesse Ruderman, Tyson Smith, Boris Zbarsky,
Randell Jesup, Olli Pettay, Karl Tomlinson, Jeff Walden, Gary Kwong,
Andrew McCreight, Georg Fritzsche, and Carsten Book discovered multiple
memory safety issues in Firefox. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit these to
cause a denial of service via application crash, or execute arbitrary
code with the privileges of the user invoking Firefox. (CVE-2015-4513,
CVE-2015-4514)
Tim Brown discovered that Firefox discloses the hostname during NTLM
authentication in some circumstances. If a user were tricked in to
opening a specially crafted website with NTLM v1 enabled, an attacker
could exploit this to obtain sensitive information
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-7181 nss: use-after-poison in sec_asn1d_parse_leaf() (MFSA 2015-133)
bugzilla·2015-10-07·CVSS 7.5
CVE-2015-7181 [HIGH] CVE-2015-7181 nss: use-after-poison in sec_asn1d_parse_leaf() (MFSA 2015-133)
CVE-2015-7181 nss: use-after-poison in sec_asn1d_parse_leaf() (MFSA 2015-133)
Mozilla engineers Tyson Smith reported a use-after-poison in the ASN.1 decoder in Network Security Services (NSS). These issues were in octet string parsing and were found through fuzzing and code inspection. If these issues were exploited, they would lead to a potentially exploitable crash.
These issues were fixed in NSS version 3.19.2.1 and 3.19.4, shipped in Firefox and Firefox ESR, respectively, as well as NSS 3.20.1.
Upstream bug:
https://bugzilla.mozilla.org/show_bug.cgi?id=1192028
External Reference:
https://www.mozilla.org/security/announce/2015/mfsa2015-133.html
https://access.redhat.com/articles/2043623
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. U
Bugzilla
ASan: use-after-poison in sec_asn1d_parse_leaf()
bugzilla·2015-08-06
[CRITICAL] ASan: use-after-poison in sec_asn1d_parse_leaf()
ASan: use-after-poison in sec_asn1d_parse_leaf()
Created attachment 8644611
call_stack.txt
Tim shared tools with me from bug 1185033.
Discussion:
Created attachment 8644612
test_case.der
---
Mass cc to get some NSS eyes on these bugs.
---
I'm assuming other versions than 42 would also be affected. Tracking for 43, for now.
---
sworkman or rbarnes can you help find an owner for this bug? Since it's sec-critical, I don't like to see it go assigned to nobody for too long. This bug has the assigned to nobody blues.
---
Keeler should able to look at this or find someone to look at it when he gets back from PTO next week.
---
Here's some debug output from the ASN.1 parsing routines:
> PLACE = beforeIdentifier, next byte = 0x24, f4400464[0]
> State: tmpl f7168540, kind SEQUENCE dur
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00037.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00049.htmlhttp://packetstormsecurity.com/files/134268/Slackware-Security-Advisory-mozilla-nss-Updates.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1980.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1981.htmlhttp://www.debian.org/security/2015/dsa-3393http://www.debian.org/security/2015/dsa-3410http://www.debian.org/security/2016/dsa-3688http://www.mozilla.org/security/announce/2015/mfsa2015-133.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/77416http://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1034069http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.399753http://www.ubuntu.com/usn/USN-2785-1http://www.ubuntu.com/usn/USN-2791-1http://www.ubuntu.com/usn/USN-2819-1https://bto.bluecoat.com/security-advisory/sa119https://bugzilla.mozilla.org/show_bug.cgi?id=1192028https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.19.2.1_release_noteshttps://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.19.4_release_noteshttps://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.20.1_release_noteshttps://security.gentoo.org/glsa/201512-10https://security.gentoo.org/glsa/201605-06http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00037.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00049.htmlhttp://packetstormsecurity.com/files/134268/Slackware-Security-Advisory-mozilla-nss-Updates.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1980.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1981.htmlhttp://www.debian.org/security/2015/dsa-3393http://www.debian.org/security/2015/dsa-3410http://www.debian.org/security/2016/dsa-3688http://www.mozilla.org/security/announce/2015/mfsa2015-133.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/77416http://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1034069http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.399753http://www.ubuntu.com/usn/USN-2785-1http://www.ubuntu.com/usn/USN-2791-1http://www.ubuntu.com/usn/USN-2819-1https://bto.bluecoat.com/security-advisory/sa119https://bugzilla.mozilla.org/show_bug.cgi?id=1192028https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.19.2.1_release_noteshttps://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.19.4_release_noteshttps://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.20.1_release_noteshttps://security.gentoo.org/glsa/201512-10https://security.gentoo.org/glsa/201605-06
2015-11-05
Published