CVE-2016-1950
published 2016-03-13CVE-2016-1950: Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before…
PriorityP348high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
4.19%
89.8th percentile
Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | iphone_os | <= 9.2.1 | — |
| apple | mac_os_x | <= 10.11.3 | — |
| apple | os_x_el_capitan_v10.11.4_and_security_update_2016-002 | — | — |
| apple | tvos | <= 9.1 | — |
| apple | tvos | — | — |
| apple | watchos | <= 2.1 | — |
| apple | watchos | — | — |
| debian | firefox | < firefox 45.0-1 (sid) | firefox 45.0-1 (sid) |
| debian | firefox-esr | < firefox 45.0-1 (sid) | firefox 45.0-1 (sid) |
| debian | nss | < firefox 45.0-1 (sid) | firefox 45.0-1 (sid) |
| mozilla | firefox | <= 44.0.2 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2016-04-27·CVSS 8.8
CVE-2016-1950 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Bob Clary, Christoph Diehl, Christian Holler, Andrew McCreight, Daniel
Holbert, Jesse Ruderman, and Randell Jesup discovered multiple memory
safety issues in Thunderbird. If a user were tricked in to opening a
specially crafted message, an attacker could potentially exploit these to
cause a denial of service via application crash, or execute arbitrary code
with the privileges of the user invoking Thunderbird. (CVE-2016-1952)
Nicolas Golubovic discovered that CSP violation reports can be used to
overwrite local files. If a user were tricked in to opening a specially
crafted website in a browsing context with addon signing disabled and
unpacked addons installed, an attacker could potentially exp
Ubuntu
Firefox regressions
vendor_ubuntu·2016-04-19·CVSS 8.8
[HIGH] Firefox regressions
Title: Firefox regressions
Summary: USN-2917-1 introduced several regressions in Firefox.
USN-2917-1 fixed vulnerabilities in Firefox. This update caused several
web compatibility regressions.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Francis Gabriel discovered a buffer overflow during ASN.1 decoding in NSS.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to cause a denial of service via
application crash, or execute arbitrary code with the privileges of the
user invoking Firefox. (CVE-2016-1950)
Bob Clary, Christoph Diehl, Christian Holler, Andrew McCreight, Daniel
Holbert, Jesse Ruderman, Randell Jesup, Carsten Book, Gian-Carlo Pascutto,
Tyson Smith, Andrea Marchesini,
Ubuntu
Firefox regressions
vendor_ubuntu·2016-04-07·CVSS 8.8
[HIGH] Firefox regressions
Title: Firefox regressions
Summary: USN-2917-1 introduced several regressions in Firefox.
USN-2917-1 fixed vulnerabilities in Firefox. This update caused several
regressions that could result in search engine settings being lost, the
list of search providers appearing empty or the location bar breaking
after typing an invalid URL. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Francis Gabriel discovered a buffer overflow during ASN.1 decoding in NSS.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to cause a denial of service via
application crash, or execute arbitrary code with the privileges of the
user invoking Firefox. (CVE-2016-1950)
Bob Clary, Christoph Diehl, Christian H
Ubuntu
NSS vulnerability
vendor_ubuntu·2016-03-09
CVE-2016-1950 NSS vulnerability
Title: NSS vulnerability
Summary: NSS could be made to crash or run programs if it received specially crafted
input.
Francis Gabriel discovered that NSS incorrectly handled decoding certain
ASN.1 data. An remote attacker could use this issue to cause NSS to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: After a standard system update you need to restart any applications that
use NSS, such as Evolution and Chromium, to make all the necessary changes.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2016-03-09·CVSS 8.8
CVE-2016-1950 [HIGH] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Francis Gabriel discovered a buffer overflow during ASN.1 decoding in NSS.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to cause a denial of service via
application crash, or execute arbitrary code with the privileges of the
user invoking Firefox. (CVE-2016-1950)
Bob Clary, Christoph Diehl, Christian Holler, Andrew McCreight, Daniel
Holbert, Jesse Ruderman, Randell Jesup, Carsten Book, Gian-Carlo Pascutto,
Tyson Smith, Andrea Marchesini, and Jukka Jylänki discovered multiple
memory safety issues in Firefox. If a user were tricked in to opening a
specially crafted website, an attacker could p
Red Hat
nss: Heap buffer overflow vulnerability in ASN1 certificate parsing (MFSA 2016-35)
vendor_redhat·2016-03-08·CVSS 8.8
CVE-2016-1950 [HIGH] nss: Heap buffer overflow vulnerability in ASN1 certificate parsing (MFSA 2016-35)
nss: Heap buffer overflow vulnerability in ASN1 certificate parsing (MFSA 2016-35)
Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.
A heap-based buffer overflow flaw was found in the way NSS parsed certain ASN.1 structures. An attacker could use this flaw to create a specially crafted certificate which, when parsed by NSS, could cause it to crash, or execute arbitrary code, using the permissions of the user running an application compiled against the NSS library.
Debian
CVE-2016-1950: firefox - Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.1...
vendor_debian·2016·CVSS 8.8
CVE-2016-1950 [HIGH] CVE-2016-1950: firefox - Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.1...
Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.
Scope: local
sid: resolved (fixed in 45.0-1)
Apple
CVE-2016-1950: tvOS 9.2
vendor_apple·CVSS 8.8
CVE-2016-1950 [HIGH] CVE-2016-1950: tvOS 9.2
Apple Security Update: About the security content of tvOS 9.2
Product: tvOS
Version: 9.2
CVE: CVE-2016-1950
Component: CVE-ID
Apple
CVE-2016-1950: iOS 9.3
vendor_apple·CVSS 8.8
CVE-2016-1950 [HIGH] CVE-2016-1950: iOS 9.3
Apple Security Update: About the security content of iOS 9.3
Product: iOS
Version: 9.3
CVE: CVE-2016-1950
Component: CVE-ID
Apple
CVE-2016-1950: watchOS 2.2
vendor_apple·CVSS 8.8
CVE-2016-1950 [HIGH] CVE-2016-1950: watchOS 2.2
Apple Security Update: About the security content of watchOS 2.2
Product: watchOS
Version: 2.2
CVE: CVE-2016-1950
Component: CVE-ID
Impact: An application may be able to execute arbitrary code with kernel privileges
Description: A memory corruption issue was addressed through improved memory handling.
Apple
CVE-2016-1950: OS X El Capitan v10.11.4 and Security Update 2016-002
vendor_apple·CVSS 8.8
CVE-2016-1950 [HIGH] CVE-2016-1950: OS X El Capitan v10.11.4 and Security Update 2016-002
Apple Security Update: About the security content of OS X El Capitan v10.11.4 and Security Update 2016-002
Product: OS X El Capitan v10.11.4 and Security Update 2016-002
CVE: CVE-2016-1950
Component: CVE-ID
GHSA
GHSA-8cv9-944x-284m: Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3
ghsa_unreviewed·2022-05-13
CVE-2016-1950 [HIGH] CWE-119 GHSA-8cv9-944x-284m: Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3
Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.
Project0
CVE-2021-30737, @xerub's 2021 iOS ASN.1 Vulnerability - Project Zero
project_zero·2022-04-01·CVSS 8.8
CVE-2021-30737 [HIGH] CVE-2021-30737, @xerub's 2021 iOS ASN.1 Vulnerability - Project Zero
Posted by Ian Beer, Google Project Zero
This blog post is my analysis of a vulnerability found by @xerub. Phrack published @xerub's writeup so go check that out first.
As well as doing my own vulnerability research I also spend time trying as best as I can to keep up with the public state-of-the-art, especially when details of a particularly interesting vulnerability are announced or a new in-the-wild exploit is caught. Originally this post was just a series of notes I took last year as I was trying to understand this bug. But the bug itself and the narrative around it are so fascinating that I thought it would be worth writing up these notes into a more coherent form to share with the community.
## Background
On April 14th 2021 the Washington Post published an article on the
OSV
thunderbird vulnerabilities
osv·2016-04-27·CVSS 8.8
CVE-2016-1952 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
Bob Clary, Christoph Diehl, Christian Holler, Andrew McCreight, Daniel
Holbert, Jesse Ruderman, and Randell Jesup discovered multiple memory
safety issues in Thunderbird. If a user were tricked in to opening a
specially crafted message, an attacker could potentially exploit these to
cause a denial of service via application crash, or execute arbitrary code
with the privileges of the user invoking Thunderbird. (CVE-2016-1952)
Nicolas Golubovic discovered that CSP violation reports can be used to
overwrite local files. If a user were tricked in to opening a specially
crafted website in a browsing context with addon signing disabled and
unpacked addons installed, an attacker could potentially exploit this to
gain additional privileges. (CVE-2016-1954)
Jose Marti
OSV
firefox regressions
osv·2016-04-19·CVSS 8.8
[HIGH] firefox regressions
firefox regressions
USN-2917-1 fixed vulnerabilities in Firefox. This update caused several
web compatibility regressions.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Francis Gabriel discovered a buffer overflow during ASN.1 decoding in NSS.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to cause a denial of service via
application crash, or execute arbitrary code with the privileges of the
user invoking Firefox. (CVE-2016-1950)
Bob Clary, Christoph Diehl, Christian Holler, Andrew McCreight, Daniel
Holbert, Jesse Ruderman, Randell Jesup, Carsten Book, Gian-Carlo Pascutto,
Tyson Smith, Andrea Marchesini, and Jukka Jylänki discovered multiple
memory safety issues in Firefox.
OSV
firefox regressions
osv·2016-04-07·CVSS 8.8
[HIGH] firefox regressions
firefox regressions
USN-2917-1 fixed vulnerabilities in Firefox. This update caused several
regressions that could result in search engine settings being lost, the
list of search providers appearing empty or the location bar breaking
after typing an invalid URL. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Francis Gabriel discovered a buffer overflow during ASN.1 decoding in NSS.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to cause a denial of service via
application crash, or execute arbitrary code with the privileges of the
user invoking Firefox. (CVE-2016-1950)
Bob Clary, Christoph Diehl, Christian Holler, Andrew McCreight, Daniel
Holbert, Jesse Ruderman, Randell Jesup,
OSV
CVE-2016-1950: Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3
osv·2016-03-13·CVSS 8.8
CVE-2016-1950 [HIGH] CVE-2016-1950: Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3
Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.
OSV
firefox vulnerabilities
osv·2016-03-09·CVSS 8.8
CVE-2016-1950 [HIGH] firefox vulnerabilities
firefox vulnerabilities
Francis Gabriel discovered a buffer overflow during ASN.1 decoding in NSS.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to cause a denial of service via
application crash, or execute arbitrary code with the privileges of the
user invoking Firefox. (CVE-2016-1950)
Bob Clary, Christoph Diehl, Christian Holler, Andrew McCreight, Daniel
Holbert, Jesse Ruderman, Randell Jesup, Carsten Book, Gian-Carlo Pascutto,
Tyson Smith, Andrea Marchesini, and Jukka Jylänki discovered multiple
memory safety issues in Firefox. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit these to
cause a denial of service via application crash, or execute arbitrary code
with the
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-1950 nss-util: nss: Heap buffer overflow vulnerability in ASN1 certificate parsing (MFSA 2016-35) [fedora-all]
bugzilla·2016-03-09·CVSS 8.8
CVE-2016-1950 [HIGH] CVE-2016-1950 nss-util: nss: Heap buffer overflow vulnerability in ASN1 certificate parsing (MFSA 2016-35) [fedora-all]
CVE-2016-1950 nss-util: nss: Heap buffer overflow vulnerability in ASN1 certificate parsing (MFSA 2016-35) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this iss
Bugzilla
CVE-2016-1950 nss: Heap buffer overflow vulnerability in ASN1 certificate parsing (MFSA 2016-35)
bugzilla·2016-02-22·CVSS 8.8
CVE-2016-1950 [HIGH] CVE-2016-1950 nss: Heap buffer overflow vulnerability in ASN1 certificate parsing (MFSA 2016-35)
CVE-2016-1950 nss: Heap buffer overflow vulnerability in ASN1 certificate parsing (MFSA 2016-35)
A heap-based buffer overflow was found in the ASN.1 parsing code of NSS. A remote attacker could create a specially-crafted certificate, which when parsed by NSS, could the application linked with NSS to crash or potentially execute code with the permission of the user running such an application.
Applications such as web browsers which parse untrusted web content are specially vulnerable to this issue.
Discussion:
Created attachment 1129399
upstream patch on top of nss 3.21, from nss 3.21.1
---
Acknowledgements:
Name: the Mozilla project
Upstream: Francis Gabriel
---
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2016-35
---
This issue has been addressed
http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00050.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00068.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00093.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00016.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0495.htmlhttp://www.debian.org/security/2016/dsa-3510http://www.debian.org/security/2016/dsa-3520http://www.debian.org/security/2016/dsa-3688http://www.mozilla.org/security/announce/2016/mfsa2016-35.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/84223http://www.securitytracker.com/id/1035215http://www.ubuntu.com/usn/USN-2917-1http://www.ubuntu.com/usn/USN-2917-2http://www.ubuntu.com/usn/USN-2917-3http://www.ubuntu.com/usn/USN-2924-1http://www.ubuntu.com/usn/USN-2934-1https://bto.bluecoat.com/security-advisory/sa119https://bugzilla.mozilla.org/show_bug.cgi?id=1245528https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.19.2.3_release_noteshttps://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.21.1_release_noteshttps://security.gentoo.org/glsa/201605-06https://support.apple.com/HT206166https://support.apple.com/HT206167https://support.apple.com/HT206168https://support.apple.com/HT206169http://lists.apple.com/archives/security-announce/2016/Mar/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2016/Mar/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00050.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00068.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00093.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00016.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0495.htmlhttp://www.debian.org/security/2016/dsa-3510http://www.debian.org/security/2016/dsa-3520http://www.debian.org/security/2016/dsa-3688http://www.mozilla.org/security/announce/2016/mfsa2016-35.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/84223http://www.securitytracker.com/id/1035215http://www.ubuntu.com/usn/USN-2917-1http://www.ubuntu.com/usn/USN-2917-2http://www.ubuntu.com/usn/USN-2917-3http://www.ubuntu.com/usn/USN-2924-1http://www.ubuntu.com/usn/USN-2934-1https://bto.bluecoat.com/security-advisory/sa119https://bugzilla.mozilla.org/show_bug.cgi?id=1245528https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.19.2.3_release_noteshttps://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.21.1_release_noteshttps://security.gentoo.org/glsa/201605-06https://support.apple.com/HT206166https://support.apple.com/HT206167https://support.apple.com/HT206168https://support.apple.com/HT206169
2016-03-13
Published