CVE-2013-1739

Priority
Medium
Description
Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that
data structures are initialized before read operations, which allows remote
attackers to cause a denial of service or possibly have unspecified other
impact via vectors that trigger a decryption failure.
References
Bugs
Assigned-to
mdeslaur
Package
Upstream:released (24.1.0)
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life)
Ubuntu 12.04 LTS (Precise Pangolin):released (1:24.1.0+build1-0ubuntu0.12.04.1)
Ubuntu 12.10 (Quantal Quetzal):released (1:24.1.0+build1-0ubuntu0.12.10.1)
Ubuntu 13.04 (Raring Ringtail):released (1:24.1.0+build1-0ubuntu0.13.04.1)
Ubuntu 13.10 (Saucy Salamander):released (1:24.1.0+build1-0ubuntu0.13.10.1)
Ubuntu 14.04 LTS (Trusty Tahr):released (1:24.1.0+build1-0ubuntu1)
Package
Source: nss (LP Ubuntu Debian)
Upstream:released (3.15.2)
Ubuntu 10.04 LTS (Lucid Lynx):released (3.15.3-0ubuntu0.10.04.1)
Ubuntu 12.04 LTS (Precise Pangolin):released (3.15.3-0ubuntu0.12.04.1)
Ubuntu 12.10 (Quantal Quetzal):released (3.15.3-0ubuntu0.12.10.1)
Ubuntu 13.04 (Raring Ringtail):released (2:3.15.3-0ubuntu0.13.04.1)
Ubuntu 13.10 (Saucy Salamander):released (2:3.15.3-0ubuntu0.13.10.1)
Ubuntu 14.04 LTS (Trusty Tahr):not-affected (2:3.15.3-1)
Patches:
Vendor:http://www.debian.org/security/2013/dsa-2790
Package
Upstream:released (25.0)
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life)
Ubuntu 12.04 LTS (Precise Pangolin):released (25.0+build3-0ubuntu0.12.04.1)
Ubuntu 12.10 (Quantal Quetzal):released (25.0+build3-0ubuntu0.12.10.1)
Ubuntu 13.04 (Raring Ringtail):released (25.0+build3-0ubuntu0.13.04.1)
Ubuntu 13.10 (Saucy Salamander):released (25.0+build3-0ubuntu0.13.10.1)
Ubuntu 14.04 LTS (Trusty Tahr):released (25.0+build3-0ubuntu0.13.10.1)
More Information

Valid XHTML 1.0 Strict

Updated: 2013-11-25 21:14:33 UTC (commit 7483)