PT-2014-1466 · Mozilla+5 · Thunderbird+8

Published

2014-05-13

·

Updated

2024-12-12

·

CVE-2014-1544

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Network Security Services (NSS) versions 3.x Firefox versions prior to 31.0 Firefox ESR versions prior to 24.7 Thunderbird versions prior to 24.7
Description The issue is related to a use-after-free vulnerability in the CERT DestroyCertificate function in libnss3.so, which allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a trust domain. This vulnerability affects Mozilla Network Security Services (NSS) and is used in Firefox, Firefox ESR, and Thunderbird.
Recommendations For Mozilla Network Security Services (NSS) version 3.x, update to a version that contains a fix for this issue. For Firefox versions prior to 31.0, update to version 31.0 or later. For Firefox ESR versions prior to 24.7, update to version 24.7 or later. For Thunderbird versions prior to 24.7, update to version 24.7 or later. As a temporary workaround, consider restricting access to the CERT DestroyCertificate function until a patch is available.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1618
ALT-PU-2014-1978
ALT-PU-2014-1979
BDU:2015-00431
BDU:2015-00460
BDU:2015-00701
CESA-2014_0916
CESA-2014_0917
CVE-2014-1544
DLA-89-1
DSA-2986-1
DSA-2996-1
DSA-3071-1
MGASA-2014-0293
OPENSUSE-SU-2014_0939-1
OPENSUSE-SU-2014_0950-1
OPENSUSE-SU-2014_0976-1
OPENSUSE-SU-2014_1100-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:10230-1
OPENSUSE-SU-2024:14572-1
RHSA-2014:0915
RHSA-2014:0916
RHSA-2014:0917
RHSA-2014:1165
RHSA-2014_0916
RHSA-2014_0917
SUSE-SU-2014_0960-1
USN-2295-1
USN-2296-1
USN-2343-1

Affected Products

Alt Linux
Centos
Firefox
Firefox Esr
Network Security Services
Red Hat
Suse
Thunderbird
Ubuntu