FS#42760 - [nss] CVE-2014-1569: ASN.1 DER decoding of lengths is too permissive

Attached to Project: Arch Linux
Opened by Remi Gacogne (rgacogne) - Wednesday, 12 November 2014, 11:04 GMT
Last edited by Evangelos Foutras (foutrelis) - Tuesday, 16 December 2014, 10:58 GMT
Task Type Bug Report
Category Security
Status Closed
Assigned To Jan de Groot (JGC)
Ionut Biru (wonder)
Architecture All
Severity High
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 1
Private No

Details

Summary:
A security issue has been found[0] in NSS, allowing an attacker to smuggle undetected arbitrary data into an ASN.1 object.

This issue has been assigned CVE-2014-1569.

Mitigation:
The problem has been fixed upstream [1] but there has not been a new release yet.
I think we should consider backporting the patch until a release is available.

[0]: https://bugzilla.mozilla.org/show_bug.cgi?id=1064670
[1]: https://hg.mozilla.org/projects/nss/rev/e9a7991380db
This task depends upon

Closed by  Evangelos Foutras (foutrelis)
Tuesday, 16 December 2014, 10:58 GMT
Reason for closing:  Fixed
Additional comments about closing:  nss 3.17.3-2
Comment by Remi Gacogne (rgacogne) - Monday, 01 December 2014, 15:58 GMT Comment by Levente Polyak (anthraxx) - Tuesday, 16 December 2014, 10:49 GMT
nss 3.17.3-2 already in the repos, this ticket can be closed

Loading...