CVE-2023-0767: Buffer Overflow
An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mishandled.
Other sources
Mozilla Network Security Services (NSS), as used in Mozilla Firefox, could allow a remote attacker to execute arbitrary code on the system, caused by an arbitrary memory write. By constructing a PKCS 12 cert bundle in such a way, a remote attacker could exploit this vulnerability using PKCS 12 Safe Bag attributes to allow for arbitrary memory writes and execute arbitrary code on the vulnerable system.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/nssto a version that resolves this vulnerability.Fixed in 0:3.44.0-13.el6_10 - Upgrade
Upgrade
redhat/nssto a version that resolves this vulnerability.Fixed in 0:3.79.0-5.el7_9 - Upgrade
Upgrade
redhat/nssto a version that resolves this vulnerability.Fixed in 0:3.79.0-11.el8_7 - Upgrade
Upgrade
redhat/nssto a version that resolves this vulnerability.Fixed in 0:3.44.0-11.el8_1 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 0:102.9.0-4.el8_1 - Upgrade
Upgrade
redhat/nssto a version that resolves this vulnerability.Fixed in 0:3.53.1-13.el8_2 - Upgrade
Upgrade
redhat/nssto a version that resolves this vulnerability.Fixed in 0:3.67.0-8.el8_4 - Upgrade
Upgrade
redhat/nssto a version that resolves this vulnerability.Fixed in 0:3.79.0-11.el8_6 - Upgrade
Upgrade
redhat/nssto a version that resolves this vulnerability.Fixed in 0:3.79.0-17.el9_1 - Upgrade
Upgrade
redhat/nssto a version that resolves this vulnerability.Fixed in 0:3.79.0-17.el9_0 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 131.0.2-2 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 128.3.1esr-1~deb11u1Fixed in 115.14.0esr-1~deb12u1Fixed in 128.3.1esr-1~deb12u1Fixed in 128.3.0esr-2Fixed in 128.3.1esr-2 - Upgrade
Upgrade
debian/nssto a version that resolves this vulnerability.Fixed in 2:3.61-1+deb11u3Fixed in 2:3.87.1-1Fixed in 2:3.105-2 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:115.16.0esr-1~deb11u1Fixed in 1:115.12.0-1~deb12u1Fixed in 1:115.16.0esr-1~deb12u1Fixed in 1:128.2.0esr-1Fixed in 1:128.3.0esr-1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 102.8 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 110 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 102.8 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 102.8 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 102.8 - Upgrade
Upgrade
redhat/nssto a version that resolves this vulnerability.Fixed in 3.88.1 - Upgrade
Upgrade
redhat/nssto a version that resolves this vulnerability.Fixed in 3.79.4 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 110 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 102.8
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-0767?
CVE-2023-0767 is a vulnerability that allows an attacker to construct a PKCS 12 cert bundle that could allow for arbitrary memory writes.
What software is affected by CVE-2023-0767?
CVE-2023-0767 affects Firefox versions less than 110, Thunderbird versions less than 102.8, and Firefox ESR versions less than 102.8.
How can an attacker exploit CVE-2023-0767?
An attacker can exploit CVE-2023-0767 by constructing a malicious PKCS 12 cert bundle that triggers mishandling of PKCS 12 Safe Bag attributes, leading to arbitrary memory writes.
What is the severity of CVE-2023-0767?
CVE-2023-0767 has a severity rating of 8.8, which is considered high.
Where can I find more information about CVE-2023-0767?
You can find more information about CVE-2023-0767 in the Mozilla security advisories: [Link to advisory 1](https://www.mozilla.org/security/advisories/mfsa2023-05/), [Link to advisory 2](https://www.mozilla.org/security/advisories/mfsa2023-07/).