Bug 1347908 (CVE-2016-2834) - CVE-2016-2834 nss: Multiple security flaws (MFSA 2016-61)
Summary: CVE-2016-2834 nss: Multiple security flaws (MFSA 2016-61)
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2016-2834
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: impact=moderate,public=20160607,repor...
: 1380171 1380172 1380173 (view as bug list)
Depends On: 1383884 1383885 1383886 1383887 1383888 1416776
Blocks: 1343293 1380228
TreeView+ depends on / blocked
 
Reported: 2016-06-18 08:40 UTC by Huzaifa S. Sidhpurwala
Modified: 2019-06-08 21:17 UTC (History)
12 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Multiple buffer handling flaws were found in the way NSS handled cryptographic data from the network. A remote attacker could use these flaws to crash an application using NSS or, possibly, execute arbitrary code with the permission of the user running the application.
Clone Of:
Environment:
Last Closed: 2016-11-16 06:12:07 UTC


Attachments (Terms of Use)
backported patch (7.94 KB, patch)
2016-10-13 16:15 UTC, Kai Engert (:kaie) (inactive account)
no flags Details | Diff


Links
System ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2016:2779 normal SHIPPED_LIVE Moderate: nss and nss-util security update 2016-11-22 13:49:09 UTC

Description Huzaifa S. Sidhpurwala 2016-06-18 08:40:05 UTC
Mozilla has updated the version of Network Security Services (NSS) library used in Firefox to NSS 3.23. This addresses four moderate rated networking security issues reported by Mozilla engineers Tyson Smith and Jed Davis. 


External Reference:

https://www.mozilla.org/security/announce/2016/mfsa2016-61.html


Acknowledgements:

Name: the Mozilla project
Upstream: Tyson Smith and Jed Davis

Comment 3 Huzaifa S. Sidhpurwala 2016-06-18 08:48:39 UTC
These security flaws were fixed in nss-3.23

Fedora 22 and Fedora 23 already contains nss-3.24 and therefore is not affected by these flaws.

Comment 4 Huzaifa S. Sidhpurwala 2016-10-03 02:55:17 UTC
Mitigation:

Do not use NSS to parse untrusted certificates.

Comment 9 Kai Engert (:kaie) (inactive account) 2016-10-13 16:14:51 UTC
(In reply to Huzaifa S. Sidhpurwala from comment #2)
> This flaw corresponds to the following upstream commits:
> 
> https://hg.mozilla.org/projects/nss/rev/8d78a5ae260a
> https://hg.mozilla.org/projects/nss/rev/1ba7cd83c672
> https://hg.mozilla.org/projects/nss/rev/5fde729fdbff
> https://hg.mozilla.org/projects/nss/rev/329932eb1700

The patches apply cleanly on top of each other in the following order:
https://hg.mozilla.org/projects/nss/rev/8d78a5ae260a
https://hg.mozilla.org/projects/nss/rev/5fde729fdbff
https://hg.mozilla.org/projects/nss/rev/1ba7cd83c672
https://hg.mozilla.org/projects/nss/rev/329932eb1700

I recommend to add the following very minor change, which only affects test code, but was made before the above changes, so including it makes sense for completeness:
https://hg.mozilla.org/projects/nss/rev/b6bcbd62e833

I have merged all those changes into a single patch, which I'm attaching to the bug.

The patches seem isolated, without references to other code. Backporting should be safe.

Comment 10 Kai Engert (:kaie) (inactive account) 2016-10-13 16:15:28 UTC
Created attachment 1210200 [details]
backported patch

Comment 11 Kai Engert (:kaie) (inactive account) 2016-10-13 16:29:52 UTC
*** Bug 1380171 has been marked as a duplicate of this bug. ***

Comment 12 Kai Engert (:kaie) (inactive account) 2016-10-13 16:29:55 UTC
*** Bug 1380172 has been marked as a duplicate of this bug. ***

Comment 13 Kai Engert (:kaie) (inactive account) 2016-10-13 16:29:56 UTC
*** Bug 1380173 has been marked as a duplicate of this bug. ***

Comment 15 errata-xmlrpc 2016-11-16 05:59:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6
  Red Hat Enterprise Linux 7
  Red Hat Enterprise Linux 5

Via RHSA-2016:2779 https://rhn.redhat.com/errata/RHSA-2016-2779.html


Note You need to log in before you can comment on or make changes to this bug.