[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2994-1 nss -- nss

ID: oval:org.secpod.oval:def:601739Date: (C)2014-08-06   (M)2024-02-19
Class: PATCHFamily: unix




Several vulnerabilities have been discovered in nss, the Mozilla Network Security Service library: CVE-2013-1741 Runaway memset in certificate parsing on 64-bit computers leading to a crash by attempting to write 4Gb of nulls. CVE-2013-5606 Certificate validation with the verifylog mode did not return validation errors, but instead expected applications to determine the status by looking at the log. CVE-2014-1491 Ticket handling protection mechanisms bypass due to the lack of restriction of public values in Diffie-Hellman key exchanges. CVE-2014-1492 Incorrect IDNA domain name matching for wildcard certificates could allow specially-crafted invalid certificates to be considered as valid.

Platform:
Debian 7.0
Product:
libnss3
Reference:
DSA-2994-1
CVE-2013-1741
CVE-2013-5606
CVE-2014-1491
CVE-2014-1492
CVE    4
CVE-2013-5606
CVE-2014-1492
CVE-2014-1491
CVE-2013-1741
...
CPE    2
cpe:/a:mozilla:libnss3
cpe:/o:debian:debian_linux:7.x

© SecPod Technologies