CVE-2016-1950
Summary
| CVE | CVE-2016-1950 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-03-13 18:59:00 UTC |
| Updated | 2019-12-27 16:08:00 UTC |
| Description | Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Iphone Os | All | All | All | All |
| Operating System | Apple | Mac Os X | All | All | All | All |
| Operating System | Apple | Tvos | All | All | All | All |
| Operating System | Apple | Watchos | All | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
| Application | Mozilla | Firefox Esr | 38.0 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.0.1 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.0.5 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.1.0 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.1.1 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.2.0 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.2.1 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.3.0 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.4.0 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.5.0 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.5.1 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.6.0 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.6.1 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.0 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.0.1 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.0.5 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.1.0 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.1.1 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.2.0 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.2.1 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.3.0 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.4.0 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.5.0 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.5.1 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.6.0 | All | All | All |
| Application | Mozilla | Firefox Esr | 38.6.1 | All | All | All |
| Application | Mozilla | Network Security Services | 3.19.2 | All | All | All |
| Application | Mozilla | Network Security Services | 3.20 | All | All | All |
| Application | Mozilla | Network Security Services | 3.20.1 | All | All | All |
| Application | Mozilla | Network Security Services | 3.21 | All | All | All |
| Application | Mozilla | Network Security Services | 3.19.2 | All | All | All |
| Application | Mozilla | Network Security Services | 3.20 | All | All | All |
| Application | Mozilla | Network Security Services | 3.20.1 | All | All | All |
| Application | Mozilla | Network Security Services | 3.21 | All | All | All |
| Operating System | Opensuse | Opensuse | 13.1 | All | All | All |
| Operating System | Opensuse | Opensuse | 13.1 | All | All | All |
| Application | Oracle | Glassfish Server | 2.1.1 | All | All | All |
| Application | Oracle | Glassfish Server | 2.1.1 | All | All | All |
| Application | Oracle | Iplanet Web Proxy Server | 4.0 | All | All | All |
| Application | Oracle | Iplanet Web Proxy Server | 4.0 | All | All | All |
| Application | Oracle | Iplanet Web Server | 7.0 | All | All | All |
| Application | Oracle | Iplanet Web Server | 7.0 | All | All | All |
| Operating System | Oracle | Linux | 5.0 | All | All | All |
| Operating System | Oracle | Linux | 6 | All | All | All |
| Operating System | Oracle | Linux | 7 | All | All | All |
| Operating System | Oracle | Linux | 5.0 | All | All | All |
| Operating System | Oracle | Linux | 6 | All | All | All |
| Operating System | Oracle | Linux | 7 | All | All | All |
| Operating System | Oracle | Vm Server | 3.2 | All | All | All |
| Operating System | Oracle | Vm Server | 3.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| APPLE-SA-2016-03-21-2 watchOS 2.2 | APPLE | lists.apple.com | Mailing List |
| USN-2917-3: Firefox regressions | Ubuntu | UBUNTU | www.ubuntu.com | |
| APPLE-SA-2016-03-21-5 OS X El Capitan 10.11.4 and Security Update 2016-002 | APPLE | lists.apple.com | Mailing List |
| [security-announce] SUSE-SU-2016:0909-1: important: Security update for | SUSE | lists.opensuse.org | |
| Debian -- Security Information -- DSA-3520-1 icedove | DEBIAN | www.debian.org | |
| APPLE-SA-2016-03-21-3 tvOS 9.2 | APPLE | lists.apple.com | Mailing List |
| USN-2934-1: Thunderbird vulnerabilities | Ubuntu | UBUNTU | www.ubuntu.com | |
| USN-2917-1: Firefox vulnerabilities | Ubuntu | UBUNTU | www.ubuntu.com | |
| Debian -- Security Information -- DSA-3510-1 iceweasel | DEBIAN | www.debian.org | |
| Mozilla Products: Multiple vulnerabilities (GLSA 201605-06) — Gentoo security | GENTOO | security.gentoo.org | |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| Oracle Critical Patch Update - October 2016 | CONFIRM | www.oracle.com | Third Party Advisory |
| [security-announce] openSUSE-SU-2016:0733-1: important: Security update | SUSE | lists.opensuse.org | |
| About the security content of watchOS 2.2 - Apple Support | CONFIRM | support.apple.com | Third Party Advisory |
| About the security content of iOS 9.3 - Apple Support | CONFIRM | support.apple.com | Third Party Advisory |
| [security-announce] SUSE-SU-2016:0820-1: important: Security update for | SUSE | lists.opensuse.org | |
| [security-announce] openSUSE-SU-2016:1557-1: important: Security update | SUSE | lists.opensuse.org | Third Party Advisory |
| Mozilla Firefox Multiple Flaws Let Remote Users Execute Arbitrary Code, Spoof the Address Bar, Overwrite Files, and Deny Service - SecurityTracker | SECTRACK | www.securitytracker.com | |
| Debian -- Security Information -- DSA-3688-1 nss | DEBIAN | www.debian.org | |
| Oracle VM Server for x86 Bulletin - July 2016 | CONFIRM | www.oracle.com | Third Party Advisory |
| NSS 3.19.2.3 release notes - Mozilla | MDN | CONFIRM | developer.mozilla.org | Release Notes |
| [security-announce] openSUSE-SU-2016:0731-1: important: Security update | SUSE | lists.opensuse.org | |
| [security-announce] SUSE-SU-2016:0777-1: important: Security update for | SUSE | lists.opensuse.org | |
| Oracle Linux Bulletin - January 2016 | CONFIRM | www.oracle.com | Third Party Advisory |
| APPLE-SA-2016-03-21-1 iOS 9.3 | APPLE | lists.apple.com | Mailing List |
| Buffer overflow during ASN.1 decoding in NSS — Mozilla | CONFIRM | www.mozilla.org | Vendor Advisory |
| USN-2917-2: Firefox regressions | Ubuntu | UBUNTU | www.ubuntu.com | |
| USN-2924-1: NSS vulnerability | Ubuntu | UBUNTU | www.ubuntu.com | |
| NSS 3.21.1 release notes - Mozilla | MDN | CONFIRM | developer.mozilla.org | Release Notes |
| About the security content of OS X El Capitan v10.11.4 and Security Update 2016-002 - Apple Support | CONFIRM | support.apple.com | Third Party Advisory |
| Broadcom Support Portal | CONFIRM | bto.bluecoat.com | |
| About the security content of tvOS 9.2 - Apple Support | CONFIRM | support.apple.com | Third Party Advisory |
| Access Denied | CONFIRM | bugzilla.mozilla.org | Issue Tracking |
| Oracle Critical Patch Update - July 2017 | CONFIRM | www.oracle.com | |
| Oracle Critical Patch Update - October 2017 | CONFIRM | www.oracle.com | |
| Mozilla Network Security Services CVE-2016-1950 Heap Buffer Overflow Vulnerability | BID | www.securityfocus.com | |
| [security-announce] SUSE-SU-2016:0727-1: important: Security update for | SUSE | lists.opensuse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.