MEDIUM · 5.0

CVE-2013-0791

The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x ...

Vulnerability Description

The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted certificate.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
MozillaFirefox<= 20.0
MozillaNetwork Security Services< 3.15
MozillaSeamonkey< 2.17
MozillaThunderbird< 17.0.5
MozillaThunderbird Esr>= 17.0, < 17.0.5
CanonicalUbuntu Linux10.04
OracleVm Server3.2
RedhatEnterprise Linux Desktop5.0
RedhatEnterprise Linux Eus5.9
RedhatEnterprise Linux Server5.0
RedhatEnterprise Linux Server Aus5.9
RedhatEnterprise Linux Workstation5.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-0791?

CVE-2013-0791 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x ...

How severe is CVE-2013-0791?

CVE-2013-0791 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-0791?

Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox, Mozilla Network Security Services, Mozilla Seamonkey, Mozilla Thunderbird, Mozilla Thunderbird Esr.