FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2013-1739

This CVE name corresponds to:

Entered Topic
2013-10-30 mozilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2013-1739
Phase Assigned(20130213)

Description

Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure.

References

Source Reference
BUGTRAQ 20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities
FULLDISC 20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=894370
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=1012656
CONFIRM https://developer.mozilla.org/en-US/docs/NSS/NSS_3.15.2_release_notes
CONFIRM http://www.mozilla.org/security/announce/2013/mfsa2013-93.html
CONFIRM http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
CONFIRM http://www.vmware.com/security/advisories/VMSA-2014-0012.html
CONFIRM http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
CONFIRM http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
DEBIAN DSA-2790
GENTOO GLSA-201406-19
REDHAT RHSA-2013:1791
REDHAT RHSA-2013:1829
SUSE openSUSE-SU-2013:1539
SUSE openSUSE-SU-2013:1542
SUSE SUSE-SU-2013:1678
UBUNTU USN-2030-1
OVAL oval:org.mitre.oval:def:19254