CVE-2016-1979
published 2016-03-13CVE-2016-1979: Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in…
PriorityP337high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
2.17%
80.3th percentile
Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 45.0-1 (sid) | firefox 45.0-1 (sid) |
| debian | firefox-esr | < firefox 45.0-1 (sid) | firefox 45.0-1 (sid) |
| debian | nss | < firefox 45.0-1 (sid) | firefox 45.0-1 (sid) |
| mozilla | firefox | <= 44.0.2 | — |
| mozilla | network_security_services | <= 3.21 | — |
| mozilla | nss | >= 0 < 2:3.21-1 | 2:3.21-1 |
| mozilla | nss | >= 0 < 2:3.21-1 | 2:3.21-1 |
| mozilla | nss | >= 0 < 2:3.21-1 | 2:3.21-1 |
| mozilla | nss | >= 0 < 2:3.21-1 | 2:3.21-1 |
| mozilla | thunderbird | >= 0 < 1:38.8.0+build1-0ubuntu0.14.04.1 | 1:38.8.0+build1-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:38.8.0+build1-0ubuntu0.16.04.1 | 1:38.8.0+build1-0ubuntu0.16.04.1 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2016-05-19·CVSS 6.5
CVE-2016-1938 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Christian Holler, Tyson Smith, and Phil Ringalda discovered multiple
memory safety issues in Thunderbird. If a user were tricked in to opening
a specially crafted message, an attacker could potentially exploit these
to cause a denial of service via application crash, or execute arbitrary
code. (CVE-2016-2805, CVE-2016-2807)
Hanno Böck discovered that calculations with mp_div and mp_exptmod in NSS
produce incorrect results in some circumstances, resulting in
cryptographic weaknesses. (CVE-2016-1938)
A use-after-free was discovered in ssl3_HandleECDHServerKeyExchange in
NSS. A remote attacker could potentially exploit this to cause a denial of
service via application crash, or execute arbitrary
Red Hat
nss: Use-after-free during processing of DER encoded keys in NSS (MFSA 2016-36)
vendor_redhat·2016-03-08·CVSS 8.8
CVE-2016-1979 [HIGH] nss: Use-after-free during processing of DER encoded keys in NSS (MFSA 2016-36)
nss: Use-after-free during processing of DER encoded keys in NSS (MFSA 2016-36)
Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.
A use-after-free flaw was found in the way NSS processed certain DER (Distinguished Encoding Rules) encoded cryptographic keys. An attacker could use this flaw to create a specially crafted DER encoded certificate which, when parsed by an application compiled against the NSS library, could cause that application to crash, or execute arbitrary code using the permissions of the user running the app
Debian
CVE-2016-1979: firefox - Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey fun...
vendor_debian·2016·CVSS 8.8
CVE-2016-1979 [HIGH] CVE-2016-1979: firefox - Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey fun...
Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.
Scope: local
sid: resolved (fixed in 45.0-1)
GHSA
GHSA-3v3j-hr3p-qv6j: Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3
ghsa_unreviewed·2022-05-17
CVE-2016-1979 [HIGH] GHSA-3v3j-hr3p-qv6j: Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3
Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.
OSV
thunderbird vulnerabilities
osv·2016-05-19·CVSS 6.5
CVE-2016-2805 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
Christian Holler, Tyson Smith, and Phil Ringalda discovered multiple
memory safety issues in Thunderbird. If a user were tricked in to opening
a specially crafted message, an attacker could potentially exploit these
to cause a denial of service via application crash, or execute arbitrary
code. (CVE-2016-2805, CVE-2016-2807)
Hanno Böck discovered that calculations with mp_div and mp_exptmod in NSS
produce incorrect results in some circumstances, resulting in
cryptographic weaknesses. (CVE-2016-1938)
A use-after-free was discovered in ssl3_HandleECDHServerKeyExchange in
NSS. A remote attacker could potentially exploit this to cause a denial of
service via application crash, or execute arbitrary code. (CVE-2016-1978)
A use-after-free was discovered in PK11_Impo
OSV
CVE-2016-1979: Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3
osv·2016-03-13·CVSS 8.8
CVE-2016-1979 [HIGH] CVE-2016-1979: Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3
Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-1979 CVE-2016-1978 nss: various flaws [fedora-all]
bugzilla·2016-03-09·CVSS 7.3
CVE-2016-1979 [HIGH] CVE-2016-1979 CVE-2016-1978 nss: various flaws [fedora-all]
CVE-2016-1979 CVE-2016-1978 nss: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
Bugzilla
CVE-2016-1979 nss: Use-after-free during processing of DER encoded keys in NSS (MFSA 2016-36)
bugzilla·2016-03-07·CVSS 8.8
CVE-2016-1979 [HIGH] CVE-2016-1979 nss: Use-after-free during processing of DER encoded keys in NSS (MFSA 2016-36)
CVE-2016-1979 nss: Use-after-free during processing of DER encoded keys in NSS (MFSA 2016-36)
Mozilla developer Tim Taubert used the Address Sanitizer tool and software fuzzing to discover a use-after-free vulnerability while processing DER encoded keys in the Network Security Services (NSS) libraries. The vulnerability overwrites the freed memory with zeroes. This issue has been addressed in NSS 3.21.1, shipping in Firefox 45.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2016-36
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Tim Taubert
---
Created nss tracking bugs for this issue:
Affects: fedora-all [bug 1316003]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:0591 https://r
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00050.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00068.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00093.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0591.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0684.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0685.htmlhttp://www.debian.org/security/2016/dsa-3576http://www.debian.org/security/2016/dsa-3688http://www.mozilla.org/security/announce/2016/mfsa2016-36.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/84221http://www.securitytracker.com/id/1035215http://www.ubuntu.com/usn/USN-2973-1https://bto.bluecoat.com/security-advisory/sa124https://bugzilla.mozilla.org/show_bug.cgi?id=1185033https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.21.1_release_noteshttps://security.gentoo.org/glsa/201605-06http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00050.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00068.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00093.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0591.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0684.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0685.htmlhttp://www.debian.org/security/2016/dsa-3576http://www.debian.org/security/2016/dsa-3688http://www.mozilla.org/security/announce/2016/mfsa2016-36.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/84221http://www.securitytracker.com/id/1035215http://www.ubuntu.com/usn/USN-2973-1https://bto.bluecoat.com/security-advisory/sa124https://bugzilla.mozilla.org/show_bug.cgi?id=1185033https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.21.1_release_noteshttps://security.gentoo.org/glsa/201605-06
2016-03-13
Published