[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2013:269 -- Mandriva firefox

ID: oval:org.secpod.oval:def:1300252Date: (C)2013-12-10   (M)2024-02-19
Class: PATCHFamily: unix




Multiple security issues was identified and fixed in mozilla NSPR, NSS and firefox: Mozilla Network Security Services before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure . Integer overflow in Mozilla Network Security Services 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large size value . The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext . Mozilla Network Security Services 3.14 before 3.14.5 and 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid handshake packets . The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate . Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime before 4.10.2, as used in Firefox before 25.0.1, Firefox ESR 17.x before 17.0.11 and 24.x before 24.1.1, and SeaMonkey before 2.22.1, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted X.509 certificate, a related issue to CVE-2013-1741 . The mozilla firefox packages has been upgraded to the latest ESR version , the NSPR packages has been upgraded to the 4.10.2 version and the NSS packages has been upgraded to the 3.15.3 version which is unaffected by these security flaws. Additionally the rootcerts packages has been upgraded with the latest certdata.txt file as of 2013/11/11 from mozilla.

Platform:
Mandriva Enterprise Server 5.2
Product:
firefox
Reference:
MDVSA-2013:269
CVE-2013-1739
CVE-2013-1741
CVE-2013-2566
CVE-2013-5605
CVE-2013-5606
CVE-2013-5607
CVE    6
CVE-2013-5605
CVE-2013-5606
CVE-2013-1739
CVE-2013-2566
...
CPE    1
cpe:/o:mandriva:enterprise_server:5.2

© SecPod Technologies