Bug 1116198 (CVE-2014-1544)
Summary: | CVE-2014-1544 nss: Race-condition in certificate verification can lead to Remote code execution (MFSA 2014-63) | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Huzaifa S. Sidhpurwala <huzaifas> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | urgent | Docs Contact: | |
Priority: | urgent | ||
Version: | unspecified | CC: | carnil, emaldona, jrusnack, mpoole, security-response-team |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | nss 3.16.2 | Doc Type: | Bug Fix |
Doc Text: |
A race condition was found in the way NSS verified certain certificates. A remote attacker could use this flaw to crash an application using NSS or, possibly, execute arbitrary code with the privileges of the user running that application.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2014-07-23 05:21:18 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1032472, 1113849, 1116199, 1116200, 1116201, 1116202, 1117716, 1117717, 1117718, 1117731, 1136716 | ||
Bug Blocks: | 1116215 |
Description
Huzaifa S. Sidhpurwala
2014-07-04 02:53:21 UTC
This issue has been addressed in following products: Red Hat Enterprise Linux 5.6 Long Life Red Hat Enterprise Linux 5.9 EUS - Server Only Red Hat Enterprise Linux 6.2 AUS Red Hat Enterprise Linux 6.4 EUS - Server and Compute Node Only Via RHSA-2014:0915 https://rhn.redhat.com/errata/RHSA-2014-0915.html This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2014:0917 https://rhn.redhat.com/errata/RHSA-2014-0917.html This issue has been addressed in following products: Red Hat Enterprise Linux 7 Red Hat Enterprise Linux 5 Via RHSA-2014:0916 https://rhn.redhat.com/errata/RHSA-2014-0916.html This issue has been addressed upstream in nss 3.16.2. Fedora 19 and Fedora 20 already ships nss-3.16.2 via the following advisories: https://admin.fedoraproject.org/updates/FEDORA-2014-8047/nss-3.16.2-1.fc19,nss-softokn-3.16.2-1.fc19,nss-util-3.16.2-1.fc19 https://admin.fedoraproject.org/updates/FEDORA-2014-7941/nss-util-3.16.2-1.fc20,nss-softokn-3.16.2-1.fc20,nss-3.16.2-1.fc20 IssueDescription: A race condition was found in the way NSS verified certain certificates. A remote attacker could use this flaw to crash an application using NSS or, possibly, execute arbitrary code with the privileges of the user running that application. This issue has been addressed in following products: Red Hat Enterprise Linux 4 Extended Lifecycle Support Via RHSA-2014:1165 https://rhn.redhat.com/errata/RHSA-2014-1165.html |