First published: Mon Dec 15 2014(Updated: )
Mozilla Network Security Services (NSS) could allow a remote attacker to bypass security restrictions, caused by the failure to ensure that the DER encoding of an ASN.1 length is properly formed by the definite_length_decoder function. An attacker could exploit this vulnerability using a long byte sequence for an encoding to bypass restrictions and conduct data-smuggling attacks.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Network Security Services | <=3.16.2.3 | |
Mozilla Network Security Services | =3.16.2.0 | |
Mozilla Network Security Services | =3.16.2.1 | |
Mozilla Network Security Services | =3.16.2.2 | |
Mozilla Network Security Services | =3.17.0 | |
Mozilla Network Security Services | =3.17.1 | |
Mozilla Network Security Services | =3.17.2 | |
IBM Cognos Analytics | <=12.0.0-12.0.3 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.