CVE-2015-7183
published 2015-11-05CVE-2015-7183: Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and…
PriorityP341high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
6.79%
93.3th percentile
Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nspr | < nspr 2:4.10.10-1 (bookworm) | nspr 2:4.10.10-1 (bookworm) |
| debian | virtualbox | < nspr 2:4.10.10-1 (bookworm) | nspr 2:4.10.10-1 (bookworm) |
| mozilla | firefox | <= 41.0.2 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 0 < 42.0+build2-0ubuntu0.14.04.1 | 42.0+build2-0ubuntu0.14.04.1 |
| mozilla | network_security_services | <= 3.19.2.0 | — |
| mozilla | network_security_services | — | — |
| mozilla | thunderbird | >= 0 < 1:38.4.0+build3-0ubuntu0.14.04.1 | 1:38.4.0+build3-0ubuntu0.14.04.1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2015-12-01·CVSS 7.5
CVE-2015-4513 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Christian Holler, David Major, Jesse Ruderman, Tyson Smith, Boris Zbarsky,
Randell Jesup, Olli Pettay, Karl Tomlinson, Jeff Walden, and Gary Kwong
discovered multiple memory safety issues in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2015-4513)
Tyson Smith and David Keeler discovered a use-after-poison and buffer
overflow in NSS. An attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user
Ubuntu
NSPR vulnerability
vendor_ubuntu·2015-11-04
CVE-2015-7183 NSPR vulnerability
Title: NSPR vulnerability
Summary: NSPR could be made to crash or run programs if it received specially
crafted input.
Ryan Sleevi discovered that NSPR incorrectly handled memory allocation. A
remote attacker could use this issue to cause NSPR to crash, resulting in a
denial of service, or possibly execute arbitrary code.
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2015-11-04·CVSS 7.5
CVE-2015-4513 [HIGH] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Christian Holler, David Major, Jesse Ruderman, Tyson Smith, Boris Zbarsky,
Randell Jesup, Olli Pettay, Karl Tomlinson, Jeff Walden, Gary Kwong,
Andrew McCreight, Georg Fritzsche, and Carsten Book discovered multiple
memory safety issues in Firefox. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit these to
cause a denial of service via application crash, or execute arbitrary
code with the privileges of the user invoking Firefox. (CVE-2015-4513,
CVE-2015-4514)
Tim Brown discovered that Firefox discloses the hostname during NTLM
authentication in some circumstances. If a user were tricked in to
opening
Red Hat
nspr: heap-buffer overflow in PL_ARENA_ALLOCATE (MFSA 2015-133)
vendor_redhat·2015-11-03·CVSS 7.5
CVE-2015-7183 [HIGH] CWE-190 nspr: heap-buffer overflow in PL_ARENA_ALLOCATE (MFSA 2015-133)
nspr: heap-buffer overflow in PL_ARENA_ALLOCATE (MFSA 2015-133)
Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.
A heap-based buffer overflow was found in NSPR. An attacker could use this flaw to cause NSPR to crash or execute arbitrary code with the permissions of the user running an application compiled against the NSPR library.
Package: nspr (Red Hat Enterprise Linux 4) - Will not fix
Debian
CVE-2015-7183: nspr - Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Ru...
vendor_debian·2015·CVSS 7.5
CVE-2015-7183 [HIGH] CVE-2015-7183: nspr - Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Ru...
Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 2:4.10.10-1)
bullseye: resolved (fixed in 2:4.10.10-1)
forky: resolved (fixed in 2:4.10.10-1)
sid: resolved (fixed in 2:4.10.10-1)
trixie: resolved (fixed in 2:4.10.10-1)
GHSA
GHSA-v8r8-vg3r-9r36: Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3
ghsa_unreviewed·2022-05-17
CVE-2015-7183 [HIGH] CWE-119 GHSA-v8r8-vg3r-9r36: Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3
Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.
OSV
thunderbird vulnerabilities
osv·2015-12-01·CVSS 7.5
CVE-2015-4513 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
Christian Holler, David Major, Jesse Ruderman, Tyson Smith, Boris Zbarsky,
Randell Jesup, Olli Pettay, Karl Tomlinson, Jeff Walden, and Gary Kwong
discovered multiple memory safety issues in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2015-4513)
Tyson Smith and David Keeler discovered a use-after-poison and buffer
overflow in NSS. An attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking Thunderbird. (CVE-2015-7181,
CVE-2015-7182)
Ryan Sleevi d
OSV
CVE-2015-7183: Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3
osv·2015-11-05·CVSS 7.5
CVE-2015-7183 [HIGH] CVE-2015-7183: Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3
Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.
OSV
firefox vulnerabilities
osv·2015-11-04·CVSS 7.5
[HIGH] firefox vulnerabilities
firefox vulnerabilities
Christian Holler, David Major, Jesse Ruderman, Tyson Smith, Boris Zbarsky,
Randell Jesup, Olli Pettay, Karl Tomlinson, Jeff Walden, Gary Kwong,
Andrew McCreight, Georg Fritzsche, and Carsten Book discovered multiple
memory safety issues in Firefox. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit these to
cause a denial of service via application crash, or execute arbitrary
code with the privileges of the user invoking Firefox. (CVE-2015-4513,
CVE-2015-4514)
Tim Brown discovered that Firefox discloses the hostname during NTLM
authentication in some circumstances. If a user were tricked in to
opening a specially crafted website with NTLM v1 enabled, an attacker
could exploit this to obtain sensitive information
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-7183 nspr: heap-buffer overflow in PL_ARENA_ALLOCATE (MFSA 2015-133)
bugzilla·2015-10-07·CVSS 7.5
CVE-2015-7183 [HIGH] CVE-2015-7183 nspr: heap-buffer overflow in PL_ARENA_ALLOCATE (MFSA 2015-133)
CVE-2015-7183 nspr: heap-buffer overflow in PL_ARENA_ALLOCATE (MFSA 2015-133)
Google security engineer Ryan Sleevi reported an integer overflow in the Netscape Portable Runtime (NSPR) due to a lack of checks during memory allocation. This leads to a potentially exploitable crash. This issue is fixed in NSPR 4.10.10. The NSPR library is a required component of NSS.
Upstream bug:
https://bugzilla.mozilla.org/show_bug.cgi?id=1205157
External Reference:
https://www.mozilla.org/security/announce/2015/mfsa2015-133.html
https://access.redhat.com/articles/2043623
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Ryan Sleevi as the original reporter.
Discussion:
Upstream commits:
http://hg.mozilla.org/projects/nspr/rev/c9c965
Bugzilla
NSPR overflow in PL_ARENA_ALLOCATE can lead to crash (under ASAN), potential memory corruption
bugzilla·2015-09-16
[MEDIUM] NSPR overflow in PL_ARENA_ALLOCATE can lead to crash (under ASAN), potential memory corruption
NSPR overflow in PL_ARENA_ALLOCATE can lead to crash (under ASAN), potential memory corruption
Consider the following (simple) application, which uses NSS (rather than NSPR directly)
#include
int main(int argc, char** argv)
{
PLArenaPool* temparena = NULL;
temparena = PORT_NewArena(2048);
if (temparena == NULL) return -1; // Fatal allocation error
void* foo = PORT_ArenaAlloc(temparena, 808464432);
if (foo == NULL) return 0; // Benign allocation failure (too large)
PORT_FreeArena(temparena, PR_FALSE);
return 0;
}
Run the above application with
ASAN_OPTIONS=verbosity=3:allocator_may_return_null=1 ./a.out
And see it crash with a message somewhat similar to the followin:
Trying to unpoison memory region [0xf4900fa0, 0x24c03fd0)
The crash is on the PORT_ArenaAlloc call, which, if you dig
http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00037.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00049.htmlhttp://packetstormsecurity.com/files/134268/Slackware-Security-Advisory-mozilla-nss-Updates.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1980.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1981.htmlhttp://www.debian.org/security/2015/dsa-3393http://www.debian.org/security/2015/dsa-3406http://www.mozilla.org/security/announce/2015/mfsa2015-133.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/77415http://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1034069http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.399753http://www.ubuntu.com/usn/USN-2785-1http://www.ubuntu.com/usn/USN-2790-1http://www.ubuntu.com/usn/USN-2819-1https://bto.bluecoat.com/security-advisory/sa119https://bugzilla.mozilla.org/show_bug.cgi?id=1205157https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.19.2.1_release_noteshttps://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.19.4_release_noteshttps://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.20.1_release_noteshttps://security.gentoo.org/glsa/201512-10https://security.gentoo.org/glsa/201605-06http://lists.opensuse.org/opensuse-security-announce/2015-11/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-11/msg00025.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00037.htmlhttp://lists.opensuse.org/opensuse-updates/2015-12/msg00049.htmlhttp://packetstormsecurity.com/files/134268/Slackware-Security-Advisory-mozilla-nss-Updates.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1980.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1981.htmlhttp://www.debian.org/security/2015/dsa-3393http://www.debian.org/security/2015/dsa-3406http://www.mozilla.org/security/announce/2015/mfsa2015-133.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/77415http://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1034069http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.399753http://www.ubuntu.com/usn/USN-2785-1http://www.ubuntu.com/usn/USN-2790-1http://www.ubuntu.com/usn/USN-2819-1https://bto.bluecoat.com/security-advisory/sa119https://bugzilla.mozilla.org/show_bug.cgi?id=1205157https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.19.2.1_release_noteshttps://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.19.4_release_noteshttps://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.20.1_release_noteshttps://security.gentoo.org/glsa/201512-10https://security.gentoo.org/glsa/201605-06
2015-11-05
Published