CVE-2023-0767: Buffer Overflow

Published Feb 14, 2023
·
Updated

An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mishandled.

Other sources

Mozilla Network Security Services (NSS), as used in Mozilla Firefox, could allow a remote attacker to execute arbitrary code on the system, caused by an arbitrary memory write. By constructing a PKCS 12 cert bundle in such a way, a remote attacker could exploit this vulnerability using PKCS 12 Safe Bag attributes to allow for arbitrary memory writes and execute arbitrary code on the vulnerable system.

IBM

Affected Software

26 affected componentsFixes available
redhat/nss<0:3.44.0-13.el6_10
0:3.44.0-13.el6_10
redhat/nss<0:3.79.0-5.el7_9
0:3.79.0-5.el7_9
redhat/nss<0:3.79.0-11.el8_7
0:3.79.0-11.el8_7
redhat/nss<0:3.44.0-11.el8_1
0:3.44.0-11.el8_1
redhat/firefox<0:102.9.0-4.el8_1
0:102.9.0-4.el8_1
redhat/nss<0:3.53.1-13.el8_2
0:3.53.1-13.el8_2
redhat/nss<0:3.67.0-8.el8_4
0:3.67.0-8.el8_4
redhat/nss<0:3.79.0-11.el8_6
0:3.79.0-11.el8_6
redhat/nss<0:3.79.0-17.el9_1
0:3.79.0-17.el9_1
redhat/nss<0:3.79.0-17.el9_0
0:3.79.0-17.el9_0
IBM Cognos Analytics<=12.0.0-12.0.3
IBM Cognos Analytics<=11.2.0-11.2.4 FP4
debian/firefox
131.0.2-2
debian/firefox-esr
115.14.0esr-1~deb11u1128.3.1esr-1~deb11u1115.14.0esr-1~deb12u1128.3.1esr-1~deb12u1128.3.0esr-2128.3.1esr-2
debian/nss
2:3.61-1+deb11u32:3.87.1-12:3.105-2
debian/thunderbird
1:115.12.0-1~deb11u11:115.16.0esr-1~deb11u11:115.12.0-1~deb12u11:115.16.0esr-1~deb12u11:128.2.0esr-11:128.3.0esr-1
Mozilla Thunderbird<102.8
102.8
Mozilla Firefox<110.0
Mozilla Firefox ESR<102.8
Mozilla Thunderbird<102.8
Mozilla Firefox<110
110
Mozilla Firefox ESR<102.8
102.8
redhat/firefox<102.8
102.8
redhat/thunderbird<102.8
102.8
redhat/nss<3.88.1
3.88.1
redhat/nss<3.79.4
3.79.4

Event History

Feb 14, 2023
CVE Published
12:00 AM
Feb 16, 2023
Data Sourced
via Red Hat·09:09 AM
DescriptionSeverityAffected Software
Jun 2, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
05:15 PM
Description
Jan 12, 2024
Data Sourced
via Launchpad·12:13 AM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·03:45 AM
RemedyDescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2023-0767?

CVE-2023-0767 is a vulnerability that allows an attacker to construct a PKCS 12 cert bundle that could allow for arbitrary memory writes.

2

What software is affected by CVE-2023-0767?

CVE-2023-0767 affects Firefox versions less than 110, Thunderbird versions less than 102.8, and Firefox ESR versions less than 102.8.

3

How can an attacker exploit CVE-2023-0767?

An attacker can exploit CVE-2023-0767 by constructing a malicious PKCS 12 cert bundle that triggers mishandling of PKCS 12 Safe Bag attributes, leading to arbitrary memory writes.

4

What is the severity of CVE-2023-0767?

CVE-2023-0767 has a severity rating of 8.8, which is considered high.

5

Where can I find more information about CVE-2023-0767?

You can find more information about CVE-2023-0767 in the Mozilla security advisories: [Link to advisory 1](https://www.mozilla.org/security/advisories/mfsa2023-05/), [Link to advisory 2](https://www.mozilla.org/security/advisories/mfsa2023-07/).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203