CVE-2015-7182
published 2015-11-05CVE-2015-7182: Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before…
PriorityP349critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
10.24%
95.2th percentile
Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nss | < nss 2:3.20.1-1 (bookworm) | nss 2:3.20.1-1 (bookworm) |
| mozilla | firefox | <= 41.0.2 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 42.0+build2-0ubuntu0.14.04.1 | 42.0+build2-0ubuntu0.14.04.1 |
| mozilla | network_security_services | <= 3.19.2.0 | — |
| mozilla | network_security_services | — | — |
| mozilla | nss | >= 0 < 2:3.20.1-1 | 2:3.20.1-1 |
| mozilla | nss | >= 0 < 2:3.20.1-1 | 2:3.20.1-1 |
| mozilla | nss | >= 0 < 2:3.20.1-1 | 2:3.20.1-1 |
| mozilla | nss | >= 0 < 2:3.20.1-1 | 2:3.20.1-1 |
| mozilla | thunderbird | >= 0 < 1:38.4.0+build3-0ubuntu0.14.04.1 | 1:38.4.0+build3-0ubuntu0.14.04.1 |
| oracle | glassfish_server | — | — |
| oracle | iplanet_web_proxy_server | — | — |
| oracle | iplanet_web_server | — | — |
| oracle | opensso | — | — |
| oracle | traffic_director | — | — |
| oracle | traffic_director | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2015-12-01·CVSS 7.5
CVE-2015-4513 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Christian Holler, David Major, Jesse Ruderman, Tyson Smith, Boris Zbarsky,
Randell Jesup, Olli Pettay, Karl Tomlinson, Jeff Walden, and Gary Kwong
discovered multiple memory safety issues in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2015-4513)
Tyson Smith and David Keeler discovered a use-after-poison and buffer
overflow in NSS. An attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user
Ubuntu
NSS vulnerabilities
vendor_ubuntu·2015-11-04
CVE-2015-7181 NSS vulnerabilities
Title: NSS vulnerabilities
Summary: NSS could be made to crash or run programs if it received specially
crafted input.
Tyson Smith and David Keeler discovered that NSS incorrectly handled
decoding certain ASN.1 data. An remote attacker could use this issue to
cause NSS to crash, resulting in a denial of service, or possibly execute
arbitrary code.
Instructions: After a standard system update you need to restart any applications that
use NSS, such as Evolution and Chromium, to make all the necessary changes.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2015-11-04·CVSS 7.5
CVE-2015-4513 [HIGH] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Christian Holler, David Major, Jesse Ruderman, Tyson Smith, Boris Zbarsky,
Randell Jesup, Olli Pettay, Karl Tomlinson, Jeff Walden, Gary Kwong,
Andrew McCreight, Georg Fritzsche, and Carsten Book discovered multiple
memory safety issues in Firefox. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit these to
cause a denial of service via application crash, or execute arbitrary
code with the privileges of the user invoking Firefox. (CVE-2015-4513,
CVE-2015-4514)
Tim Brown discovered that Firefox discloses the hostname during NTLM
authentication in some circumstances. If a user were tricked in to
opening
Red Hat
nss: ASN.1 decoder heap overflow when decoding constructed OCTET STRING that mixes indefinite and definite length encodings (MFSA 2015-133)
vendor_redhat·2015-11-03·CVSS 9.8
CVE-2015-7182 [CRITICAL] CWE-122 nss: ASN.1 decoder heap overflow when decoding constructed OCTET STRING that mixes indefinite and definite length encodings (MFSA 2015-133)
nss: ASN.1 decoder heap overflow when decoding constructed OCTET STRING that mixes indefinite and definite length encodings (MFSA 2015-133)
Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data.
A heap-based buffer overflow flaw was found in the way NSS parsed certain ASN.1 structures. An attacker could use this flaw to cause NSS to crash or execute arbitrary code with the permissions of the user running an application compiled against the NSS library.
Package: nss (Red Hat Enterprise Linux
Debian
CVE-2015-7182: nss - Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Serv...
vendor_debian·2015·CVSS 9.8
CVE-2015-7182 [CRITICAL] CVE-2015-7182: nss - Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Serv...
Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data.
Scope: local
bookworm: resolved (fixed in 2:3.20.1-1)
bullseye: resolved (fixed in 2:3.20.1-1)
forky: resolved (fixed in 2:3.20.1-1)
sid: resolved (fixed in 2:3.20.1-1)
trixie: resolved (fixed in 2:3.20.1-1)
GHSA
GHSA-f3ww-87xf-9498: Heap-based buffer overflow in the ASN
ghsa_unreviewed·2022-05-17
CVE-2015-7182 [CRITICAL] CWE-119 GHSA-f3ww-87xf-9498: Heap-based buffer overflow in the ASN
Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data.
OSV
thunderbird vulnerabilities
osv·2015-12-01·CVSS 7.5
CVE-2015-4513 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
Christian Holler, David Major, Jesse Ruderman, Tyson Smith, Boris Zbarsky,
Randell Jesup, Olli Pettay, Karl Tomlinson, Jeff Walden, and Gary Kwong
discovered multiple memory safety issues in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2015-4513)
Tyson Smith and David Keeler discovered a use-after-poison and buffer
overflow in NSS. An attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking Thunderbird. (CVE-2015-7181,
CVE-2015-7182)
Ryan Sleevi d
OSV
CVE-2015-7182: Heap-based buffer overflow in the ASN
osv·2015-11-05·CVSS 9.8
CVE-2015-7182 [CRITICAL] CVE-2015-7182: Heap-based buffer overflow in the ASN
Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data.
OSV
firefox vulnerabilities
osv·2015-11-04·CVSS 7.5
[HIGH] firefox vulnerabilities
firefox vulnerabilities
Christian Holler, David Major, Jesse Ruderman, Tyson Smith, Boris Zbarsky,
Randell Jesup, Olli Pettay, Karl Tomlinson, Jeff Walden, Gary Kwong,
Andrew McCreight, Georg Fritzsche, and Carsten Book discovered multiple
memory safety issues in Firefox. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit these to
cause a denial of service via application crash, or execute arbitrary
code with the privileges of the user invoking Firefox. (CVE-2015-4513,
CVE-2015-4514)
Tim Brown discovered that Firefox discloses the hostname during NTLM
authentication in some circumstances. If a user were tricked in to
opening a specially crafted website with NTLM v1 enabled, an attacker
could exploit this to obtain sensitive information
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-7182 nss: ASN.1 decoder heap overflow when decoding constructed OCTET STRING that mixes indefinite and definite length encodings (MFSA 2015-133)
bugzilla·2015-10-07·CVSS 9.8
CVE-2015-7182 [CRITICAL] CVE-2015-7182 nss: ASN.1 decoder heap overflow when decoding constructed OCTET STRING that mixes indefinite and definite length encodings (MFSA 2015-133)
CVE-2015-7182 nss: ASN.1 decoder heap overflow when decoding constructed OCTET STRING that mixes indefinite and definite length encodings (MFSA 2015-133)
Mozilla engineers David Keeler reported a buffer overflow in the ASN.1 decoder in Network Security Services (NSS). These issues were in octet string parsing and were found through fuzzing and code inspection. If these issues were exploited, they would lead to a potentially exploitable crash.
These issues were fixed in NSS version 3.19.2.1 and 3.19.4, shipped in Firefox and Firefox ESR, respectively, as well as NSS 3.20.1.
Upstream bug:
https://bugzilla.mozilla.org/show_bug.cgi?id=1202868
External Reference:
https://www.mozilla.org/security/announce/2015/mfsa2015-133.html
https://access.redhat.com/articles/2043623
Acknowledgements:
Bugzilla
ASN.1 decoder heap overflow when decoding constructed OCTET STRING that mixes indefinite and definite length encodings
bugzilla·2015-09-08
[MEDIUM] ASN.1 decoder heap overflow when decoding constructed OCTET STRING that mixes indefinite and definite length encodings
ASN.1 decoder heap overflow when decoding constructed OCTET STRING that mixes indefinite and definite length encodings
Created attachment 8658396
checkcert.c
I discovered this when investigating bug 1192028. Consider the following ASN.1:
24 0A [OCTET STRING | CONSTRUCTED] [length is 10 bytes]
24 80 [OCTET STRING | CONSTRUCTED] [indefinite length]
04 01 01 [OCTET STRING] [length is 1] [value is 1]
00 00 [end of indefinite length contents marker]
04 01 02 [OCTET STRING] [length is 1] [value is 2]
If I understand correctly, this is valid ASN.1 and is equivalent to 04 02 01 02 (i.e. an OCTET STRING of length 2 with value 01 02).
However, under ASAN using a setup similar to bug 1192028 (see attached), this results in a use-after-poison that I believe could be parleyed into a heap overflow.
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00037.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00049.htmlhttp://packetstormsecurity.com/files/134268/Slackware-Security-Advisory-mozilla-nss-Updates.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1980.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1981.htmlhttp://www.debian.org/security/2015/dsa-3393http://www.debian.org/security/2015/dsa-3410http://www.debian.org/security/2016/dsa-3688http://www.mozilla.org/security/announce/2015/mfsa2015-133.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/77416http://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1034069http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.399753http://www.ubuntu.com/usn/USN-2785-1http://www.ubuntu.com/usn/USN-2791-1http://www.ubuntu.com/usn/USN-2819-1https://bto.bluecoat.com/security-advisory/sa119https://bugzilla.mozilla.org/show_bug.cgi?id=1202868https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.19.2.1_release_noteshttps://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.19.4_release_noteshttps://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.20.1_release_noteshttps://security.gentoo.org/glsa/201512-10https://security.gentoo.org/glsa/201605-06http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00037.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00049.htmlhttp://packetstormsecurity.com/files/134268/Slackware-Security-Advisory-mozilla-nss-Updates.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1980.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1981.htmlhttp://www.debian.org/security/2015/dsa-3393http://www.debian.org/security/2015/dsa-3410http://www.debian.org/security/2016/dsa-3688http://www.mozilla.org/security/announce/2015/mfsa2015-133.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/77416http://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1034069http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.399753http://www.ubuntu.com/usn/USN-2785-1http://www.ubuntu.com/usn/USN-2791-1http://www.ubuntu.com/usn/USN-2819-1https://bto.bluecoat.com/security-advisory/sa119https://bugzilla.mozilla.org/show_bug.cgi?id=1202868https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.19.2.1_release_noteshttps://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.19.4_release_noteshttps://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.20.1_release_noteshttps://security.gentoo.org/glsa/201512-10https://security.gentoo.org/glsa/201605-06
2015-11-05
Published