- Description
- Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messenger (AIM), allows remote SSL servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long domain name in the subject's Common Name (CN) field of an X.509 certificate, related to the cert_TestHostName function.
- Source
- secalert@redhat.com
- NVD status
- Modified
CVSS 2.0
- Type
- Primary
- Base score
- 9.3
- Impact score
- 10
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:C/I:C/A:C
- nvd@nist.gov
- CWE-119
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mozilla:network_security_services:3.12.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "000A1698-C9DE-49A1-9F5D-FDED34A134E8"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:aol:instant_messenger:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E8DF7CEB-81F5-46FC-9588-AF5326957C89"
},
{
"criteria": "cpe:2.3:a:gnome:evolution:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6606C39B-8137-44B6-A96E-E0B8F67FAFFB"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "14E6A30E-7577-4569-9309-53A0AF7FE3AC"
},
{
"criteria": "cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "138701FB-929A-4683-B41F-CB014ACFE44A"
},
{
"criteria": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D5C8E657-3049-4462-98F6-296C60BC8C5C"
},
{
"criteria": "cpe:2.3:a:pidgin:pidgin:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "87A0BF9F-F7E9-4196-BEF7-800B4C850990"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
]