Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Firefox | Mozilla | * | 44.0.2 (including) |
Red Hat Enterprise Linux 5 | RedHat | nspr-0:4.11.0-1.el5_11 | * |
Red Hat Enterprise Linux 5 | RedHat | nss-0:3.21.0-6.el5_11 | * |
Red Hat Enterprise Linux 6 | RedHat | nspr-0:4.11.0-0.1.el6_7 | * |
Red Hat Enterprise Linux 6 | RedHat | nss-0:3.21.0-0.3.el6_7 | * |
Red Hat Enterprise Linux 6 | RedHat | nss-util-0:3.21.0-0.3.el6_7 | * |
Red Hat Enterprise Linux 7 | RedHat | nspr-0:4.11.0-1.el7_2 | * |
Red Hat Enterprise Linux 7 | RedHat | nss-0:3.21.0-9.el7_2 | * |
Red Hat Enterprise Linux 7 | RedHat | nss-softokn-0:3.16.2.3-14.2.el7_2 | * |
Red Hat Enterprise Linux 7 | RedHat | nss-util-0:3.21.0-2.2.el7_2 | * |
Firefox | Ubuntu | precise | * |
Firefox | Ubuntu | trusty | * |
Firefox | Ubuntu | upstream | * |
Firefox | Ubuntu | wily | * |
Nss | Ubuntu | upstream | * |
Nss | Ubuntu | vivid/stable-phone-overlay | * |
Thunderbird | Ubuntu | devel | * |
Thunderbird | Ubuntu | precise | * |
Thunderbird | Ubuntu | trusty | * |
Thunderbird | Ubuntu | upstream | * |
Thunderbird | Ubuntu | wily | * |
Thunderbird | Ubuntu | xenial | * |
Thunderbird | Ubuntu | yakkety | * |
Thunderbird | Ubuntu | zesty | * |