CVE-2023-0767: Buffer Overflow
An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mishandled.
Other sources
Mozilla Network Security Services (NSS), as used in Mozilla Firefox, could allow a remote attacker to execute arbitrary code on the system, caused by an arbitrary memory write. By constructing a PKCS 12 cert bundle in such a way, a remote attacker could exploit this vulnerability using PKCS 12 Safe Bag attributes to allow for arbitrary memory writes and execute arbitrary code on the vulnerable system.
— IBM
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-0767?
CVE-2023-0767 is a vulnerability that allows an attacker to construct a PKCS 12 cert bundle that could allow for arbitrary memory writes.
What software is affected by CVE-2023-0767?
CVE-2023-0767 affects Firefox versions less than 110, Thunderbird versions less than 102.8, and Firefox ESR versions less than 102.8.
How can an attacker exploit CVE-2023-0767?
An attacker can exploit CVE-2023-0767 by constructing a malicious PKCS 12 cert bundle that triggers mishandling of PKCS 12 Safe Bag attributes, leading to arbitrary memory writes.
What is the severity of CVE-2023-0767?
CVE-2023-0767 has a severity rating of 8.8, which is considered high.
Where can I find more information about CVE-2023-0767?
You can find more information about CVE-2023-0767 in the Mozilla security advisories: [Link to advisory 1](https://www.mozilla.org/security/advisories/mfsa2023-05/), [Link to advisory 2](https://www.mozilla.org/security/advisories/mfsa2023-07/).