Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-1569
Description:The definite_length_decoder function in lib/util/quickder.c in Mozilla Network Security Services (NSS) before 3.16.2.4 and 3.17.x before 3.17.3 does not ensure that the DER encoding of an ASN.1 length is properly formed, which allows remote attackers to conduct data- smuggling attacks by using a long byte sequence for an encoding, as demonstrated by the SEC_QuickDERDecodeItem function's improper handling of an arbitrary-length encoding of 0x00.
Test IDs: 1.3.6.1.4.1.25623.1.1.4.2015.0171.1   1.3.6.1.4.1.25623.1.0.851048   1.3.6.1.4.1.25623.1.0.850755   1.3.6.1.4.1.25623.1.1.4.2015.0173.1   1.3.6.1.4.1.25623.1.1.1.2.2015.154   1.3.6.1.4.1.25623.1.1.4.2015.0180.1   1.3.6.1.4.1.25623.1.0.703186   1.3.6.1.4.1.25623.1.0.842063   1.3.6.1.4.1.25623.1.0.868720  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-1569
Debian Security Information: DSA-3186 (Google Search)
http://www.debian.org/security/2015/dsa-3186
http://www.intelsecurity.com/resources/wp-berserk-analysis-part-1.pdf
https://www.imperialviolet.org/2014/09/26/pkcs1.html
https://www.reddit.com/r/netsec/comments/2hd1m8/rsa_signature_forgery_in_nss/cksnr02
http://www.securitytracker.com/id/1032909
SuSE Security Announcement: SUSE-SU-2015:0171 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00032.html
SuSE Security Announcement: SUSE-SU-2015:0173 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00033.html
SuSE Security Announcement: SUSE-SU-2015:0180 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00036.html
SuSE Security Announcement: openSUSE-SU-2015:0138 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00024.html
SuSE Security Announcement: openSUSE-SU-2015:0404 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00000.html




© 1998-2025 E-Soft Inc. All rights reserved.