5
CVSSv2

CVE-2012-0441

Published: 05/06/2012 Updated: 18/01/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (NSS) prior to 3.13.4, as used in Firefox 4.x up to and including 12.0, Firefox ESR 10.x prior to 10.0.5, Thunderbird 5.0 up to and including 12.0, Thunderbird ESR 10.x prior to 10.0.5, and SeaMonkey prior to 2.10, allows remote malicious users to cause a denial of service (application crash) via a zero-length item, as demonstrated by (1) a zero-length basic constraint or (2) a zero-length field in an OCSP response.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 4.0

mozilla firefox 5.0

mozilla firefox 5.0.1

mozilla firefox 8.0.1

mozilla firefox 9.0.1

mozilla firefox esr 10.0

mozilla firefox esr 10.0.1

mozilla thunderbird 6.0.2

mozilla thunderbird 7.0.1

mozilla thunderbird 10.0.1

mozilla thunderbird 10.0

mozilla thunderbird 10.0.4

mozilla thunderbird esr 10.0.4

mozilla seamonkey

mozilla seamonkey 2.8

mozilla seamonkey 2.7

mozilla seamonkey 2.6.1

mozilla seamonkey 2.5

mozilla seamonkey 2.4

mozilla seamonkey 2.3

mozilla firefox 7.0

mozilla firefox 8.0

mozilla firefox 12.0

mozilla thunderbird 6.0

mozilla thunderbird 6.0.1

mozilla thunderbird 10.0.2

mozilla thunderbird 10.0.3

mozilla thunderbird esr 10.0.2

mozilla thunderbird esr 10.0.3

mozilla seamonkey 2.6

mozilla seamonkey 2.4.1

mozilla seamonkey 2.3.1

mozilla seamonkey 2.3.2

mozilla seamonkey 2.1

mozilla seamonkey 2.0.8

mozilla seamonkey 2.0.7

mozilla seamonkey 2.0.13

mozilla seamonkey 2.0.10

mozilla seamonkey 2.0

mozilla seamonkey 1.1.17

mozilla seamonkey 1.1.7

mozilla seamonkey 1.1.12

mozilla seamonkey 1.1

mozilla seamonkey 1.5.0.9

mozilla seamonkey 1.0.9

mozilla seamonkey 1.1.13

mozilla network security services

mozilla network security services 3.12.2

mozilla network security services 3.7.3

mozilla network security services 3.7.5

mozilla network security services 3.4.1

mozilla network security services 3.4.2

mozilla network security services 3.2

mozilla network security services 3.9

mozilla firefox 4.0.1

mozilla firefox 6.0

mozilla firefox 6.0.2

mozilla firefox 9.0

mozilla firefox 10.0.2

mozilla firefox 10.0

mozilla firefox esr 10.0.2

mozilla firefox esr 10.0.3

mozilla thunderbird 7.0

mozilla thunderbird 8.0

mozilla thunderbird 11.0

mozilla thunderbird 12.0

mozilla seamonkey 2.9

mozilla seamonkey 2.3.3

mozilla seamonkey 2.2

mozilla seamonkey 2.0.6

mozilla seamonkey 2.0.5

mozilla seamonkey 1.1.19

mozilla seamonkey 1.1.14

mozilla seamonkey 1.1.15

mozilla seamonkey 1.1.11

mozilla seamonkey 1.0

mozilla seamonkey 1.1.4

mozilla seamonkey 1.0.6

mozilla seamonkey 1.5.0.10

mozilla seamonkey 1.0.5

mozilla seamonkey 1.0.4

mozilla network security services 3.6.1

mozilla network security services 3.7

mozilla network security services 3.3

mozilla network security services 3.3.1

mozilla network security services 3.11.2

mozilla network security services 3.11.5

mozilla firefox 6.0.1

mozilla firefox 7.0.1

mozilla firefox 10.0.1

mozilla firefox 11.0

mozilla firefox esr 10.0.4

mozilla thunderbird 5.0

mozilla thunderbird 9.0.1

mozilla thunderbird 9.0

mozilla thunderbird esr 10.0

mozilla thunderbird esr 10.0.1

mozilla seamonkey 2.7.1

mozilla seamonkey 2.7.2

mozilla seamonkey 2.0.2

mozilla seamonkey 2.0.1

mozilla seamonkey 2.0.12

mozilla seamonkey 2.0.4

mozilla seamonkey 1.1.18

mozilla seamonkey 1.1.8

mozilla seamonkey 1.1.6

mozilla seamonkey 1.1.9

mozilla seamonkey 1.1.5

mozilla seamonkey 1.5.0.8

mozilla seamonkey 1.1.3

mozilla seamonkey 1.1.2

mozilla seamonkey 1.0.3

mozilla seamonkey 1.0.2

mozilla network security services 3.7.1

mozilla network security services 3.7.2

mozilla network security services 3.3.2

mozilla network security services 3.4

mozilla network security services 3.11.4

mozilla network security services 3.2.1

mozilla seamonkey 2.0.11

mozilla seamonkey 2.0.9

mozilla seamonkey 2.0.14

mozilla seamonkey 2.0.3

mozilla seamonkey 1.1.16

mozilla seamonkey 1.1.1

mozilla seamonkey 1.1.10

mozilla seamonkey 1.0.8

mozilla seamonkey 1.0.7

mozilla seamonkey 1.0.1

mozilla network security services 3.12.1

mozilla network security services 3.12

mozilla network security services 3.7.7

mozilla network security services 3.8

mozilla network security services 3.5

mozilla network security services 3.6

mozilla network security services 3.11.3

Vendor Advisories

Synopsis Moderate: nss and nspr security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic Updated nss and nspr packages that fix two security issues, several bugs,and add various enhancements are now available for Red HatEnterprise Linux 5The Red Hat Security Response Team h ...
Synopsis Moderate: nss, nspr, and nss-util security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic Updated nss, nss-util, and nspr packages that fix one security issue,several bugs, and add various enhancements are now available for Red HatEnterprise Linux 6The Red Hat Sec ...
NSS could be made to crash if it opened a specially crafted certificate ...
NSS could be made to crash if it opened a specially crafted certificate ...
Several security issues were fixed in Firefox ...
Several security issues were fixed in Thunderbird ...
Several security issues were fixed in Thunderbird ...
USN-1463-1 introduced regressions in Firefox ...
A flaw was found in the way the ASN1 (Abstract Syntax Notation One) decoder in NSS handled zero length items This flaw could cause the decoder to incorrectly skip or replace certain items with a default value, or could cause an application to crash if, for example, it received a specially-crafted OCSP (Online Certificate Status Protocol) response ...
Mozilla Foundation Security Advisory 2012-39 NSS parsing errors with zero length items Announced June 5, 2012 Reporter Kaspar Brand Impact Moderate Products Firefox, Firefox ESR, SeaMonkey, Thunderbird, Thunderbird ESR ...