Vulnerability   
Search   
    Search 191973 CVE descriptions
and 86218 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.702790
Category:Debian Local Security Checks
Title:Debian Security Advisory DSA 2790-1 (nss - uninitialized memory read)
Summary:A flaw was found in the way the Mozilla Network Security Service library;(nss) read uninitialized data when there was a decryption failure. A;remote attacker could use this flaw to cause a denial of service;(application crash) for applications linked with the nss library.;;The oldstable distribution (squeeze) is not affected by this problem.
Description:Summary:
A flaw was found in the way the Mozilla Network Security Service library
(nss) read uninitialized data when there was a decryption failure. A
remote attacker could use this flaw to cause a denial of service
(application crash) for applications linked with the nss library.

The oldstable distribution (squeeze) is not affected by this problem.

Affected Software/OS:
nss on Debian Linux

Solution:
For the stable distribution (wheezy), this problem has been fixed in
version 2:3.14.4-1.

The packages in the stable distribution were updated to the latest patch
release 3.14.4 of the library to also include a regression bugfix for a
flaw that affects the libpkix certificate verification cache.

For the testing distribution (jessie), this problem has been fixed in
version 2:3.15.2-1.

For the unstable distribution (sid), this problem has been fixed in
version 2:3.15.2-1.

We recommend that you upgrade your nss packages.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2013-1739
BugTraq ID: 62966
http://www.securityfocus.com/bid/62966
Bugtraq: 20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities (Google Search)
http://www.securityfocus.com/archive/1/534161/100/0/threaded
Debian Security Information: DSA-2790 (Google Search)
http://www.debian.org/security/2013/dsa-2790
http://seclists.org/fulldisclosure/2014/Dec/23
http://security.gentoo.org/glsa/glsa-201406-19.xml
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19254
RedHat Security Advisories: RHSA-2013:1791
http://rhn.redhat.com/errata/RHSA-2013-1791.html
RedHat Security Advisories: RHSA-2013:1829
http://rhn.redhat.com/errata/RHSA-2013-1829.html
SuSE Security Announcement: SUSE-SU-2013:1678 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00014.html
SuSE Security Announcement: openSUSE-SU-2013:1539 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-10/msg00013.html
SuSE Security Announcement: openSUSE-SU-2013:1542 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-10/msg00016.html
http://www.ubuntu.com/usn/USN-2030-1
CopyrightCopyright (C) 2013 Greenbone Networks GmbH http://greenbone.net

This is only one of 86218 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2020 E-Soft Inc. All rights reserved.