CVE Vulnerabilities

CVE-2014-1544

Published: Jul 23, 2014 | Modified: Jan 07, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
6.8 CRITICAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a trust domain.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla * 30.0 (including)
Firefox_esr Mozilla 24.0 (including) 24.0 (including)
Firefox_esr Mozilla 24.0.1 (including) 24.0.1 (including)
Firefox_esr Mozilla 24.0.2 (including) 24.0.2 (including)
Firefox_esr Mozilla 24.1.0 (including) 24.1.0 (including)
Firefox_esr Mozilla 24.1.1 (including) 24.1.1 (including)
Firefox_esr Mozilla 24.2 (including) 24.2 (including)
Firefox_esr Mozilla 24.3 (including) 24.3 (including)
Firefox_esr Mozilla 24.4 (including) 24.4 (including)
Firefox_esr Mozilla 24.5 (including) 24.5 (including)
Firefox_esr Mozilla 24.6 (including) 24.6 (including)
Network_security_services Mozilla 3.2 (including) 3.2 (including)
Network_security_services Mozilla 3.2.1 (including) 3.2.1 (including)
Network_security_services Mozilla 3.3 (including) 3.3 (including)
Network_security_services Mozilla 3.3.1 (including) 3.3.1 (including)
Network_security_services Mozilla 3.3.2 (including) 3.3.2 (including)
Network_security_services Mozilla 3.4 (including) 3.4 (including)
Network_security_services Mozilla 3.4.1 (including) 3.4.1 (including)
Network_security_services Mozilla 3.4.2 (including) 3.4.2 (including)
Network_security_services Mozilla 3.5 (including) 3.5 (including)
Network_security_services Mozilla 3.6 (including) 3.6 (including)
Network_security_services Mozilla 3.6.1 (including) 3.6.1 (including)
Network_security_services Mozilla 3.7 (including) 3.7 (including)
Network_security_services Mozilla 3.7.1 (including) 3.7.1 (including)
Network_security_services Mozilla 3.7.2 (including) 3.7.2 (including)
Network_security_services Mozilla 3.7.3 (including) 3.7.3 (including)
Network_security_services Mozilla 3.7.5 (including) 3.7.5 (including)
Network_security_services Mozilla 3.7.7 (including) 3.7.7 (including)
Network_security_services Mozilla 3.8 (including) 3.8 (including)
Network_security_services Mozilla 3.9 (including) 3.9 (including)
Network_security_services Mozilla 3.11.2 (including) 3.11.2 (including)
Network_security_services Mozilla 3.11.3 (including) 3.11.3 (including)
Network_security_services Mozilla 3.11.4 (including) 3.11.4 (including)
Network_security_services Mozilla 3.11.5 (including) 3.11.5 (including)
Network_security_services Mozilla 3.12 (including) 3.12 (including)
Network_security_services Mozilla 3.12.1 (including) 3.12.1 (including)
Network_security_services Mozilla 3.12.2 (including) 3.12.2 (including)
Network_security_services Mozilla 3.12.3 (including) 3.12.3 (including)
Network_security_services Mozilla 3.12.3.1 (including) 3.12.3.1 (including)
Network_security_services Mozilla 3.12.3.2 (including) 3.12.3.2 (including)
Network_security_services Mozilla 3.12.4 (including) 3.12.4 (including)
Network_security_services Mozilla 3.12.5 (including) 3.12.5 (including)
Network_security_services Mozilla 3.12.6 (including) 3.12.6 (including)
Network_security_services Mozilla 3.12.7 (including) 3.12.7 (including)
Network_security_services Mozilla 3.12.8 (including) 3.12.8 (including)
Network_security_services Mozilla 3.12.9 (including) 3.12.9 (including)
Network_security_services Mozilla 3.12.10 (including) 3.12.10 (including)
Network_security_services Mozilla 3.12.11 (including) 3.12.11 (including)
Network_security_services Mozilla 3.14 (including) 3.14 (including)
Network_security_services Mozilla 3.14.1 (including) 3.14.1 (including)
Network_security_services Mozilla 3.14.2 (including) 3.14.2 (including)
Network_security_services Mozilla 3.14.3 (including) 3.14.3 (including)
Network_security_services Mozilla 3.14.4 (including) 3.14.4 (including)
Network_security_services Mozilla 3.14.5 (including) 3.14.5 (including)
Network_security_services Mozilla 3.15 (including) 3.15 (including)
Network_security_services Mozilla 3.15.1 (including) 3.15.1 (including)
Network_security_services Mozilla 3.15.2 (including) 3.15.2 (including)
Network_security_services Mozilla 3.15.3 (including) 3.15.3 (including)
Network_security_services Mozilla 3.15.3.1 (including) 3.15.3.1 (including)
Network_security_services Mozilla 3.15.4 (including) 3.15.4 (including)
Network_security_services Mozilla 3.15.5 (including) 3.15.5 (including)
Network_security_services Mozilla 3.16 (including) 3.16 (including)
Thunderbird Mozilla * 24.6 (including)
Thunderbird Mozilla 24.0 (including) 24.0 (including)
Thunderbird Mozilla 24.0.1 (including) 24.0.1 (including)
Thunderbird Mozilla 24.1 (including) 24.1 (including)
Thunderbird Mozilla 24.1.1 (including) 24.1.1 (including)
Thunderbird Mozilla 24.2 (including) 24.2 (including)
Thunderbird Mozilla 24.3 (including) 24.3 (including)
Thunderbird Mozilla 24.4 (including) 24.4 (including)
Thunderbird Mozilla 24.5 (including) 24.5 (including)
Red Hat Enterprise Linux 4 Extended Lifecycle Support RedHat nss-0:3.12.10-7.el4 *
Red Hat Enterprise Linux 5 RedHat nspr-0:4.10.6-1.el5_10 *
Red Hat Enterprise Linux 5 RedHat nss-0:3.15.3-7.el5_10 *
Red Hat Enterprise Linux 5.6 Long Life RedHat nss-0:3.12.8-9.el5_6 *
Red Hat Enterprise Linux 5.9 Extended Update Support RedHat nss-0:3.14.3-9.el5_9 *
Red Hat Enterprise Linux 6 RedHat nspr-0:4.10.6-1.el6_5 *
Red Hat Enterprise Linux 6 RedHat nss-0:3.16.1-4.el6_5 *
Red Hat Enterprise Linux 6 RedHat nss-util-0:3.16.1-1.el6_5 *
Red Hat Enterprise Linux 6.2 Advanced Update Support RedHat nss-0:3.13.1-10.el6_2 *
Red Hat Enterprise Linux 6.4 Extended Update Support RedHat nss-0:3.14.3-6.el6_4 *
Red Hat Enterprise Linux 7 RedHat nspr-0:4.10.6-1.el7_0 *
Red Hat Enterprise Linux 7 RedHat nss-0:3.15.4-7.el7_0 *
Firefox Ubuntu devel *
Firefox Ubuntu lucid *
Firefox Ubuntu precise *
Firefox Ubuntu trusty *
Firefox Ubuntu upstream *
Nss Ubuntu lucid *
Nss Ubuntu precise *
Nss Ubuntu trusty *
Nss Ubuntu upstream *
Thunderbird Ubuntu devel *
Thunderbird Ubuntu lucid *
Thunderbird Ubuntu precise *
Thunderbird Ubuntu trusty *
Thunderbird Ubuntu upstream *

References