CVE-2017-7502
published 2017-05-30CVE-2017-7502: Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote…
PriorityP338high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
4.30%
90.1th percentile
Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote attacker.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nss | < nss 2:3.26.2-1.1 (bookworm) | nss 2:3.26.2-1.1 (bookworm) |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | nss | >= 0 < 2:3.26.2-1.1 | 2:3.26.2-1.1 |
| mozilla | nss | >= 0 < 2:3.26.2-1.1 | 2:3.26.2-1.1 |
| mozilla | nss | >= 0 < 2:3.26.2-1.1 | 2:3.26.2-1.1 |
| mozilla | nss | >= 0 < 2:3.26.2-1.1 | 2:3.26.2-1.1 |
| nss_project | nss | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-97vv-2xv8-266j: Null pointer dereference vulnerability in NSS since 3
ghsa_unreviewed·2022-05-14
CVE-2017-7502 [HIGH] CWE-476 GHSA-97vv-2xv8-266j: Null pointer dereference vulnerability in NSS since 3
Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote attacker.
OSV
CVE-2017-7502: Null pointer dereference vulnerability in NSS since 3
osv·2017-05-30·CVSS 7.5
CVE-2017-7502 [HIGH] CVE-2017-7502: Null pointer dereference vulnerability in NSS since 3
Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote attacker.
Ubuntu
NSS vulnerability
vendor_ubuntu·2017-07-31·CVSS 7.5
CVE-2017-7502 [HIGH] NSS vulnerability
Title: NSS vulnerability
Summary: Several security issues were fixed in NSS.
It was discovered that NSS incorrectly handled certain empty SSLv2
messages. A remote attacker could possibly use this issue to cause NSS to
crash, resulting in a denial of service. (CVE-2017-7502)
Karthik Bhargavan and Gaetan Leurent discovered that the DES and Triple DES
ciphers were vulnerable to birthday attacks. A remote attacker could
possibly use this flaw to obtain clear text data from long encrypted
sessions. This update causes NSS to limit use of the same symmetric key.
(CVE-2016-2183)
It was discovered that NSS incorrectly handled Base64 decoding. A remote
attacker could use this flaw to cause NSS to crash, resulting in a denial
of service, or possibly execute arbitrary code. (CVE-2017-5461)
Instru
Ubuntu
NSS vulnerability
vendor_ubuntu·2017-06-21
CVE-2017-7502 NSS vulnerability
Title: NSS vulnerability
Summary: NSS could be made to crash if it received specially crafted network
traffic.
It was discovered that NSS incorrectly handled certain empty SSLv2
messages. A remote attacker could possibly use this issue to cause NSS to
crash, resulting in a denial of service.
Instructions: After a standard system update you need to restart any applications
that use NSS, such as Evolution and Chromium, to make all the necessary
changes.
Red Hat
nss: Null pointer dereference when handling empty SSLv2 messages
vendor_redhat·2017-05-30·CVSS 7.5
CVE-2017-7502 [HIGH] CWE-476 nss: Null pointer dereference when handling empty SSLv2 messages
nss: Null pointer dereference when handling empty SSLv2 messages
Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote attacker.
A null pointer dereference flaw was found in the way NSS handled empty SSLv2 messages. An attacker could use this flaw to crash a server application compiled against the NSS library.
Package: nss (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2017-7502: nss - Null pointer dereference vulnerability in NSS since 3.24.0 was found when server...
vendor_debian·2017·CVSS 7.5
CVE-2017-7502 [HIGH] CVE-2017-7502: nss - Null pointer dereference vulnerability in NSS since 3.24.0 was found when server...
Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote attacker.
Scope: local
bookworm: resolved (fixed in 2:3.26.2-1.1)
bullseye: resolved (fixed in 2:3.26.2-1.1)
forky: resolved (fixed in 2:3.26.2-1.1)
sid: resolved (fixed in 2:3.26.2-1.1)
trixie: resolved (fixed in 2:3.26.2-1.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7502 nss: Null pointer dereference when handling empty SSLv2 messages
bugzilla·2017-04-28·CVSS 7.5
CVE-2017-7502 [HIGH] CVE-2017-7502 nss: Null pointer dereference when handling empty SSLv2 messages
CVE-2017-7502 nss: Null pointer dereference when handling empty SSLv2 messages
Null pointer dereference vulnerability in NSS was found when server receives empty SSLv2 messages. This issue was introduced with the recent removal of SSLv2 protocol from upstream code in 3.24.0 and introduction of dedicated parser able to handle just sslv2-style hello messages.
Upstream patch:
https://hg.mozilla.org/projects/nss/rev/55ea60effd0d
Discussion:
*** Bug 1450763 has been marked as a duplicate of this bug. ***
---
*** Bug 1449161 has been marked as a duplicate of this bug. ***
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:1365 https://access.redhat.com/errata/RHSA-2017:1365
---
This issue has been addressed in the following products
Bugzilla
NSS server crash when handling SSLv2 hello, attempt to write to NULL buffer.
bugzilla·2017-04-26·CVSS 7.5
[HIGH] NSS server crash when handling SSLv2 hello, attempt to write to NULL buffer.
NSS server crash when handling SSLv2 hello, attempt to write to NULL buffer.
We've received a report from a user of a server software that uses NSS.
The report was seen on a RHEL 7.3 system, with NSS 3.28.2, in combination with an old nss-softokn 3.16.2.3
It's crashing in ssl3_GatherData, here:
if (v2HdrLength) {
gs->inbuf.len = 5 - v2HdrLength;
-> PORT_Memcpy(lbp, gs->hdr + v2HdrLength, gs->inbuf.len);
gs->remainder -= gs->inbuf.len;
lbp += gs->inbuf.len;
}
lbp is NULL, apparently the code expects that a destination buffer was allocated, but it hasn't.
Discussion:
Created attachment 8862110
stacktrace.1490284479.txt
attaching full stack
---
Additional information, the crash was triggered by running a Qualys vulnerability scan on the server.
Based on the stack, it seems a SSLv2 c
Bugzilla
Various ssl3_GatherData() issues
bugzilla·2017-01-02·CVSS 7.5
[HIGH] Various ssl3_GatherData() issues
Various ssl3_GatherData() issues
The fuzzing target's implementation of `recv` showed that ssl_DefRecv() can be called with buf=NULL _and_ len=0. While this isn't too bad assuming that the underlying `recv` implementation can handle it, it probably would be nice to avoid those calls. There however are a few other issues, esp. with the v2 ClientHello handling code.
Discussion:
When we receive an empty v2 record, i.e. in long form = {0x00, 0x00, 0x00, 0x00, x00}, where the last 2 bytes are appended because ssl3_GatherData() expects 5 bytes total, then we try to memcpy() into `gs->inbuf`. The problem is that `gs->inbuf.buf` is still NULL and so we have a NULL dereference. After that we set `gs->remainder` to -2 or -3 and call ssl_DefRecv() that will usually err out with PR_BUFFER_OVERFLOW_
http://www.debian.org/security/2017/dsa-3872http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.securityfocus.com/bid/98744http://www.securitytracker.com/id/1038579https://access.redhat.com/errata/RHSA-2017:1364https://access.redhat.com/errata/RHSA-2017:1365https://access.redhat.com/errata/RHSA-2017:1567https://access.redhat.com/errata/RHSA-2017:1712https://hg.mozilla.org/projects/nss/rev/55ea60effd0dhttp://www.debian.org/security/2017/dsa-3872http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.securityfocus.com/bid/98744http://www.securitytracker.com/id/1038579https://access.redhat.com/errata/RHSA-2017:1364https://access.redhat.com/errata/RHSA-2017:1365https://access.redhat.com/errata/RHSA-2017:1567https://access.redhat.com/errata/RHSA-2017:1712https://hg.mozilla.org/projects/nss/rev/55ea60effd0d
2017-05-30
Published