First published: Tue Oct 22 2013(Updated: )
Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla NSS ESR | <=3.15.1 | |
Mozilla NSS ESR | =3.12 | |
Mozilla NSS ESR | =3.12.1 | |
Mozilla NSS ESR | =3.12.2 | |
Mozilla NSS ESR | =3.12.3 | |
Mozilla NSS ESR | =3.12.3.1 | |
Mozilla NSS ESR | =3.12.3.2 | |
Mozilla NSS ESR | =3.12.4 | |
Mozilla NSS ESR | =3.12.5 | |
Mozilla NSS ESR | =3.12.6 | |
Mozilla NSS ESR | =3.12.7 | |
Mozilla NSS ESR | =3.12.8 | |
Mozilla NSS ESR | =3.12.9 | |
Mozilla NSS ESR | =3.12.10 | |
Mozilla NSS ESR | =3.12.11 | |
Mozilla NSS ESR | =3.14 | |
Mozilla NSS ESR | =3.14.1 | |
Mozilla NSS ESR | =3.14.2 | |
Mozilla NSS ESR | =3.14.3 | |
Mozilla NSS ESR | =3.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1739 has a severity rating that indicates it can cause a denial of service due to uninitialized data structures.
To fix CVE-2013-1739, update the Mozilla Network Security Services (NSS) library to version 3.15.2 or later.
CVE-2013-1739 affects Mozilla Network Security Services versions prior to 3.15.2, specifically including versions 3.15.1 and earlier.
CVE-2013-1739 can lead to denial of service and potentially other unspecified impacts due to decryption failures.
While specific exploits for CVE-2013-1739 may not be publicly documented, its nature allows for potential exploitation by remote attackers.