Mozilla NSS 'NSS_NoDB_Init()' Insecure Library Loading Arbitrary Code Execution Vulnerability
BID:50324
Info
Mozilla NSS 'NSS_NoDB_Init()' Insecure Library Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 50324 |
| Class: | Design Error |
| CVE: |
CVE-2011-3640 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 21 2011 12:00AM |
| Updated: | Dec 01 2011 09:26PM |
| Credit: | hclam |
| Vulnerable: |
SuSE openSUSE 11.4 SuSE openSUSE 11.3 Mozilla Network Security Services (NSS) 3.12.5 Mozilla Network Security Services (NSS) 3.12.3 Mozilla Network Security Services (NSS) 3.12.2 Mozilla Network Security Services (NSS) 3.11.3 Mozilla Network Security Services (NSS) 3.9.2 Mozilla Network Security Services (NSS) 3.9 Mozilla Network Security Services (NSS) 3.8 Mozilla Network Security Services (NSS) 3.7.7 Mozilla Network Security Services (NSS) 3.7.5 Mozilla Network Security Services (NSS) 3.7.3 Mozilla Network Security Services (NSS) 3.7.2 Mozilla Network Security Services (NSS) 3.7.1 Mozilla Network Security Services (NSS) 3.7 Mozilla Network Security Services (NSS) 3.6.1 Mozilla Network Security Services (NSS) 3.6 Mozilla Network Security Services (NSS) 3.5 Mozilla Network Security Services (NSS) 3.4.2 Mozilla Network Security Services (NSS) 3.4.1 Mozilla Network Security Services (NSS) 3.4 Mozilla Network Security Services (NSS) 3.3.2 Mozilla Network Security Services (NSS) 3.3.1 Mozilla Network Security Services (NSS) 3.3 Mozilla Network Security Services (NSS) 3.2.1 Mozilla Network Security Services (NSS) 3.2 Mozilla Network Security Services (NSS) 3.12.6 Mozilla Network Security Services (NSS) 3.12 Mozilla Network Security Services (NSS) 3.11 |
| Not Vulnerable: | |
Discussion
Mozilla NSS 'NSS_NoDB_Init()' Insecure Library Loading Arbitrary Code Execution Vulnerability
Mozilla Network Security Services (NSS) is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted security module.
Mozilla Network Security Services (NSS) is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted security module.
Exploit / POC
Mozilla NSS 'NSS_NoDB_Init()' Insecure Library Loading Arbitrary Code Execution Vulnerability
Attackers can exploit these issues by placing a malicious library file in the installation directory, or by tricking a user into opening a file on a remote WebDAV or SMB share.
Attackers can exploit these issues by placing a malicious library file in the installation directory, or by tricking a user into opening a file on a remote WebDAV or SMB share.
Solution / Fix
Mozilla NSS 'NSS_NoDB_Init()' Insecure Library Loading Arbitrary Code Execution Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Mozilla NSS 'NSS_NoDB_Init()' Insecure Library Loading Arbitrary Code Execution Vulnerability
References:
References: