PT-2014-1466 · Mozilla+5 · Thunderbird+8
Published
2014-05-13
·
Updated
2024-12-12
·
CVE-2014-1544
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mozilla Network Security Services (NSS) versions 3.x
Firefox versions prior to 31.0
Firefox ESR versions prior to 24.7
Thunderbird versions prior to 24.7
Description
The issue is related to a use-after-free vulnerability in the CERT DestroyCertificate function in libnss3.so, which allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a trust domain. This vulnerability affects Mozilla Network Security Services (NSS) and is used in Firefox, Firefox ESR, and Thunderbird.
Recommendations
For Mozilla Network Security Services (NSS) version 3.x, update to a version that contains a fix for this issue.
For Firefox versions prior to 31.0, update to version 31.0 or later.
For Firefox ESR versions prior to 24.7, update to version 24.7 or later.
For Thunderbird versions prior to 24.7, update to version 24.7 or later.
As a temporary workaround, consider restricting access to the CERT DestroyCertificate function until a patch is available.
Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Firefox
Firefox Esr
Network Security Services
Red Hat
Suse
Thunderbird
Ubuntu