CVE-2016-1951
published 2016-08-07CVE-2016-1951: Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (NSPR) before 4.12 allow remote attackers to cause a denial of service (buffer…
PriorityP341high8.6CVSS 3.0
AVNACLPRNUINSUCLILAH
EPSS
2.72%
84.3th percentile
Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (NSPR) before 4.12 allow remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long string to a PR_*printf function.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 45.0-1 (sid) | firefox 45.0-1 (sid) |
| debian | firefox-esr | < firefox 45.0-1 (sid) | firefox 45.0-1 (sid) |
| debian | nspr | < firefox 45.0-1 (sid) | firefox 45.0-1 (sid) |
| mozilla | netscape_portable_runtime | <= 4.11 | — |
| mozilla | thunderbird | >= 0 < 1:45.2.0+build1-0ubuntu0.14.04.3 | 1:45.2.0+build1-0ubuntu0.14.04.3 |
| mozilla | thunderbird | >= 0 < 1:45.2.0+build1-0ubuntu0.16.04.1 | 1:45.2.0+build1-0ubuntu0.16.04.1 |
CVSS provenance
nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv8.6HIGH
vendor_debian8.6HIGH
vendor_redhat8.6HIGH
vendor_ubuntu8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2xc9-w6jv-x92w: Multiple integer overflows in io/prprf
ghsa_unreviewed·2022-05-17
CVE-2016-1951 [HIGH] CWE-190 GHSA-2xc9-w6jv-x92w: Multiple integer overflows in io/prprf
Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (NSPR) before 4.12 allow remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long string to a PR_*printf function.
OSV
CVE-2016-1951: Multiple integer overflows in io/prprf
osv·2016-08-07·CVSS 8.6
CVE-2016-1951 [HIGH] CVE-2016-1951: Multiple integer overflows in io/prprf
Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (NSPR) before 4.12 allow remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long string to a PR_*printf function.
OSV
thunderbird vulnerabilities
osv·2016-07-18·CVSS 8.6
CVE-2016-1951 [HIGH] thunderbird vulnerabilities
thunderbird vulnerabilities
It was discovered that NSPR incorrectly handled memory allocation. If a
user were tricked in to opening a specially crafted message, an attacker
could potentially exploit this to cause a denial of service via
application crash, or execute arbitrary code. (CVE-2016-1951)
Christian Holler, Gary Kwong, Jesse Ruderman, Tyson Smith, Timothy Nikkel,
Sylvestre Ledru, Julian Seward, Olli Pettay, and Karl Tomlinson,
discovered multiple memory safety issues in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code. (CVE-2016-2818)
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2016-07-18·CVSS 8.6
CVE-2016-1951 [HIGH] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
It was discovered that NSPR incorrectly handled memory allocation. If a
user were tricked in to opening a specially crafted message, an attacker
could potentially exploit this to cause a denial of service via
application crash, or execute arbitrary code. (CVE-2016-1951)
Christian Holler, Gary Kwong, Jesse Ruderman, Tyson Smith, Timothy Nikkel,
Sylvestre Ledru, Julian Seward, Olli Pettay, and Karl Tomlinson,
discovered multiple memory safety issues in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code. (CVE-2016-2818)
Instructions: After a standa
Ubuntu
NSPR vulnerability
vendor_ubuntu·2016-07-11
CVE-2016-1951 NSPR vulnerability
Title: NSPR vulnerability
Summary: NSPR could be made to crash or run programs if it received specially
crafted input.
It was discovered that NSPR incorrectly handled memory allocation. A remote
attacker could use this issue to cause NSPR to crash, resulting in a denial
of service, or possibly execute arbitrary code.
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Red Hat
nspr: Memory allocation issue related to PR_*printf functions
vendor_redhat·2016-05-31·CVSS 8.6
CVE-2016-1951 [HIGH] nspr: Memory allocation issue related to PR_*printf functions
nspr: Memory allocation issue related to PR_*printf functions
Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (NSPR) before 4.12 allow remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long string to a PR_*printf function.
Package: nspr (Red Hat Enterprise Linux 5) - Will not fix
Package: nspr (Red Hat Enterprise Linux 6) - Will not fix
Package: nspr (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2016-1951: firefox - Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (N...
vendor_debian·2016·CVSS 8.6
CVE-2016-1951 [HIGH] CVE-2016-1951: firefox - Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (N...
Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (NSPR) before 4.12 allow remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long string to a PR_*printf function.
Scope: local
sid: resolved (fixed in 45.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-1951 nspr: Memory allocation issue related to PR_*printf functions
bugzilla·2016-02-23·CVSS 8.6
CVE-2016-1951 [HIGH] CVE-2016-1951 nspr: Memory allocation issue related to PR_*printf functions
CVE-2016-1951 nspr: Memory allocation issue related to PR_*printf functions
It was reported that unspecified memory allocation bug related to PR_*printf functions was fixed in nspr 4.12.
External Reference:
https://groups.google.com/forum/#!topic/mozilla.dev.tech.nspr/dV4MyMsg6jw
Discussion:
Upstream bug report:
https://bugzilla.mozilla.org/show_bug.cgi?id=1174015
Upstream commit:
https://hg.mozilla.org/projects/nspr/rev/96381e3aaae2
---
This issue was fixed in nspr-4.12
Fedora 22 and Fedora 23 currently ship nspr-4.12 and therefore is not affected by this flaw.
---
This issue will be fixed in the next nspr rebase in minor versions of RHEL 6 and 7.
---
Analysis:
There is an integer overflow followed by a heap-buffer overflow in the functions PR_vsmprintf() and PR_vsprintf_a
Bugzilla
Overflow in prprf/GrowStuff can cause memory-safety bug
bugzilla·2015-06-11
[MEDIUM] Overflow in prprf/GrowStuff can cause memory-safety bug
Overflow in prprf/GrowStuff can cause memory-safety bug
GrowStuff (38.0.1\nsprpub\pr\src\io\prprf.c) can cause an overflow if the size of the existing buffer in units of bytes (maxlen) + the size of the string to be appended (len) > 0xffffffff. In this case, the function either allocates a tiny buffer or doesn't even attempt to allocate one large enough, then writes the new string beyond the buffer's end.
1081: static int GrowStuff(SprintfState *ss, const char *sp, PRUint32 len)
1082: {
1083: ptrdiff_t off;
1084: char *newbase;
1085: PRUint32 newlen;
1086:
1087: off = ss->cur - ss->base;
1088: if (off + len >= ss->maxlen) {
1089: /* Grow the buffer */
1090: newlen = ss->maxlen + ((len > 32) ? len : 32);
1091: if (ss->base) {
1092: newbase = (char*) PR_REALLOC(ss->base, newlen);
1093: } e
http://www.securityfocus.com/bid/92385http://www.securitytracker.com/id/1036590http://www.ubuntu.com/usn/USN-3023-1https://bugzilla.mozilla.org/show_bug.cgi?id=1174015https://groups.google.com/forum/message/raw?msg=mozilla.dev.tech.nspr/dV4MyMsg6jw/hhWcXOgJDQAJhttps://hg.mozilla.org/projects/nspr/rev/96381e3aaae2http://www.securityfocus.com/bid/92385http://www.securitytracker.com/id/1036590http://www.ubuntu.com/usn/USN-3023-1https://bugzilla.mozilla.org/show_bug.cgi?id=1174015https://groups.google.com/forum/message/raw?msg=mozilla.dev.tech.nspr/dV4MyMsg6jw/hhWcXOgJDQAJhttps://hg.mozilla.org/projects/nspr/rev/96381e3aaae2
2016-08-07
Published