Bug 1031461 (CVE-2013-5607)

Summary: CVE-2013-5607 nspr: Avoid unsigned integer wrapping in PL_ArenaAllocate (MFSA 2013-103)
Product: [Other] Security Response Reporter: Huzaifa S. Sidhpurwala <huzaifas>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: barry.gestwicki.ctr, jkurik, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=moderate,public=20131119,reported=20131118,source=mozilla,cvss2=4.3/AV:N/AC:M/Au:N/C:N/I:N/A:P,rhel-5/nspr=affected,rhel-6/nspr=affected,rhel-7/nspr=notaffected,fedora-all/nspr=affected
Fixed In Version: nspr-4.10.2-1.el6_5 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---
Bug Depends On: 1031465, 1031898, 1032485, 1032488, 1033524, 1033525    
Bug Blocks: 1030811    

Description Huzaifa S. Sidhpurwala 2013-11-18 03:15:57 UTC
Pascal Cuoq, RedHat developer Kamil Dudka, and Google developer Wan-Teh Chang found a flaw similar to CVE-2013-1741 in  Netscape Portable Runtime (NSPR) library code suffered the same integer truncation.

Upstream patch:
https://hg.mozilla.org/projects/nspr/rev/4df6bc35be64

External Reference:

http://www.mozilla.org/security/announce/2013/mfsa2013-103.html


Acknowledgements:

Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Pascal Cuoq, Kamil Dudka, and Wan-Teh Chang as the original reporters of this issue.

Comment 2 Huzaifa S. Sidhpurwala 2013-11-19 05:33:32 UTC
Created nspr tracking bugs for this issue:

Affects: fedora-all [bug 1031898]

Comment 4 Tomas Hoger 2013-11-20 11:29:41 UTC
Fixed upstream in NSPR 4.10.2:

https://groups.google.com/forum/#!topic/mozilla.dev.tech.nspr/_8AcygMEjSA

Upstream bug (currently non-public):

https://bugzilla.mozilla.org/show_bug.cgi?id=927687

Comment 9 errata-xmlrpc 2013-12-05 16:16:05 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2013:1791 https://rhn.redhat.com/errata/RHSA-2013-1791.html

Comment 10 Fedora Update System 2013-12-11 02:05:08 UTC
nspr-4.10.2-1.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 11 errata-xmlrpc 2013-12-12 19:04:01 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 6

Via RHSA-2013:1829 https://rhn.redhat.com/errata/RHSA-2013-1829.html

Comment 12 Fedora Update System 2013-12-13 05:03:32 UTC
nspr-4.10.2-1.fc18 has been pushed to the Fedora 18 stable repository.  If problems still persist, please make note of it in this bug report.