Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2013.0337
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2013-0337)
Summary:The remote host is missing an update for the 'firefox, firefox-l10n, nspr, nss, rootcerts' package(s) announced via the MGASA-2013-0337 advisory.
Description:Summary:
The remote host is missing an update for the 'firefox, firefox-l10n, nspr, nss, rootcerts' package(s) announced via the MGASA-2013-0337 advisory.

Vulnerability Insight:
Updated nspr and nss packages fix security vulnerabilities:

Potentially exploitable buffer overflow in NSS before 3.15.3 that allows
remote attackers to cause a denial of service or possibly have unspecified
other impact via invalid handshake packets (CVE-2013-5605).

The CERT_VerifyCert function in lib/certhigh/certvfy.c in NSS before 3.15.3
provides an unexpected return value for an incompatible key-usage certificate
when the CERTVerifyLog argument is valid, which might allow remote attackers
to bypass intended access restrictions via a crafted certificate
(CVE-2013-5606).

Runaway memset due to an integer truncation in certificate parsing on 64-bit
computers in NSS before 3.15.3 leading to a crash by attempting to write 4Gb
of nulls (CVE-2013-1741).

Integer overflow in NSPR before 4.10.2 due to unsigned integer wrapping in
PL_ArenaAllocate (CVE-2013-5607).

NSS lowered the priority of RC4 in cipher suite advertisement so that more
secure ciphers instead of RC4 are likely to be chosen by the server, because
of plaintext recovery attacks possible with RC4 (CVE-2013-2566).

This also updates to the latest root certificate data from Mozilla.

Additionally, The latest Firefox ESR version, which fixes an issue with
translated strings not being used in some cases, is also being provided.

Affected Software/OS:
'firefox, firefox-l10n, nspr, nss, rootcerts' package(s) on Mageia 2, Mageia 3.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2013-1741
http://lists.apple.com/archives/security-announce/2015/Jun/msg00001.html
http://lists.apple.com/archives/security-announce/2015/Jun/msg00002.html
BugTraq ID: 63736
http://www.securityfocus.com/bid/63736
Bugtraq: 20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities (Google Search)
http://www.securityfocus.com/archive/1/534161/100/0/threaded
Debian Security Information: DSA-2994 (Google Search)
http://www.debian.org/security/2014/dsa-2994
http://seclists.org/fulldisclosure/2014/Dec/23
http://security.gentoo.org/glsa/glsa-201406-19.xml
https://security.gentoo.org/glsa/201504-01
RedHat Security Advisories: RHSA-2013:1791
http://rhn.redhat.com/errata/RHSA-2013-1791.html
RedHat Security Advisories: RHSA-2013:1829
http://rhn.redhat.com/errata/RHSA-2013-1829.html
SuSE Security Announcement: SUSE-SU-2013:1807 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-12/msg00000.html
SuSE Security Announcement: openSUSE-SU-2013:1732 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-11/msg00080.html
http://www.ubuntu.com/usn/USN-2030-1
http://www.ubuntu.com/usn/USN-2031-1
http://www.ubuntu.com/usn/USN-2032-1
Common Vulnerability Exposure (CVE) ID: CVE-2013-2566
BugTraq ID: 58796
http://www.securityfocus.com/bid/58796
HPdes Security Advisory: HPSBGN03324
http://marc.info/?l=bugtraq&m=143039468003789&w=2
HPdes Security Advisory: SSRT102035
http://blog.cryptographyengineering.com/2013/03/attack-of-week-rc4-is-kind-of-broken-in.html
http://cr.yp.to/talks/2013.03.12/slides.pdf
http://www.isg.rhul.ac.uk/tls/
Common Vulnerability Exposure (CVE) ID: CVE-2013-5605
BugTraq ID: 63738
http://www.securityfocus.com/bid/63738
Debian Security Information: DSA-2800 (Google Search)
http://www.debian.org/security/2013/dsa-2800
RedHat Security Advisories: RHSA-2013:1840
http://rhn.redhat.com/errata/RHSA-2013-1840.html
RedHat Security Advisories: RHSA-2013:1841
http://rhn.redhat.com/errata/RHSA-2013-1841.html
RedHat Security Advisories: RHSA-2014:0041
http://rhn.redhat.com/errata/RHSA-2014-0041.html
SuSE Security Announcement: openSUSE-SU-2013:1730 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-11/msg00078.html
Common Vulnerability Exposure (CVE) ID: CVE-2013-5606
BugTraq ID: 63737
http://www.securityfocus.com/bid/63737
Common Vulnerability Exposure (CVE) ID: CVE-2013-5607
BugTraq ID: 63802
http://www.securityfocus.com/bid/63802
Debian Security Information: DSA-2820 (Google Search)
http://www.debian.org/security/2013/dsa-2820
https://groups.google.com/forum/message/raw?msg=mozilla.dev.tech.nspr/_8AcygMEjSA/mm_cqQzLPFQJ
http://www.ubuntu.com/usn/USN-2087-1
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.