Mozilla Netscape Portable Runtime CVE-2014-1545 Out of Bounds Memory Corruption Vulnerability
BID:67975
Info
Mozilla Netscape Portable Runtime CVE-2014-1545 Out of Bounds Memory Corruption Vulnerability
| Bugtraq ID: | 67975 |
| Class: | Unknown |
| CVE: |
CVE-2014-1545 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2014 12:00AM |
| Updated: | Oct 26 2016 02:06AM |
| Credit: | Abhishek Arya (Inferno) of the Google Chrome Security Team. |
| Vulnerable: |
Ubuntu Ubuntu Linux 14.04 LTS Ubuntu Ubuntu Linux 13.10 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise Software Development Kit 11 SP3 SuSE SUSE Linux Enterprise Server 11 SP3 for VMware SuSE SUSE Linux Enterprise Server 11 SP3 SuSE SUSE Linux Enterprise Server 10 SP4 LTSS SuSE SUSE Linux Enterprise Server 10 SP3 LTSS SuSE Suse Linux Enterprise Desktop 11 SP3 SuSE Linux Enterprise Server 11 SP2 LTSS S.u.S.E. openSUSE 13.1 S.u.S.E. openSUSE 12.3 S.u.S.E. openSUSE 11.4 Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Oracle VM Server for x86 3.4 Oracle VM Server for x86 3.3 Oracle VM Server for x86 3.2 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 Mozilla Netscape Portable Runtime 4.10.4 Mozilla Netscape Portable Runtime 4.10.3 Mozilla Netscape Portable Runtime 4.10.1 Mozilla Netscape Portable Runtime 4.9.6 Mozilla Netscape Portable Runtime 4.9.5 Mozilla Netscape Portable Runtime 4.9.4 Mozilla Netscape Portable Runtime 4.8.9 Mozilla Netscape Portable Runtime 4.8.8 Mozilla Netscape Portable Runtime 4.8.7 Mozilla Netscape Portable Runtime 4.8.6 Mozilla Netscape Portable Runtime 4.8.5 Mozilla Netscape Portable Runtime 4.6.7 Mozilla Netscape Portable Runtime 4.9.3 Mozilla Netscape Portable Runtime 4.9.2 Mozilla Netscape Portable Runtime 4.9.1 Mozilla Netscape Portable Runtime 4.9 Mozilla Netscape Portable Runtime 4.8.4 Mozilla Netscape Portable Runtime 4.8.3 Mozilla Netscape Portable Runtime 4.8.2 Mozilla Netscape Portable Runtime 4.8 Mozilla Netscape Portable Runtime 4.7.6 Mozilla Netscape Portable Runtime 4.7.5 Mozilla Netscape Portable Runtime 4.7.4 Mozilla Netscape Portable Runtime 4.7.3 Mozilla Netscape Portable Runtime 4.7.2 Mozilla Netscape Portable Runtime 4.7.1 Mozilla Netscape Portable Runtime 4.7 Mozilla Netscape Portable Runtime 4.6.8 Mozilla Netscape Portable Runtime 4.6.6 Mozilla Netscape Portable Runtime 4.6.5 Mozilla Netscape Portable Runtime 4.6.4 Mozilla Netscape Portable Runtime 4.6.3 Mozilla Netscape Portable Runtime 4.6.2 Mozilla Netscape Portable Runtime 4.6.1 Mozilla Netscape Portable Runtime 4.6 Mozilla Netscape Portable Runtime 4.5.1 Mozilla Netscape Portable Runtime 4.4.1 Mozilla Netscape Portable Runtime 4.3 Mozilla Netscape Portable Runtime 4.2.2 Mozilla Netscape Portable Runtime 4.2 Mozilla Netscape Portable Runtime 4.10.5 Mozilla Netscape Portable Runtime 4.10.2 Mozilla Netscape Portable Runtime 4.10 Mozilla Netscape Portable Runtime 4.1.2 Mozilla Netscape Portable Runtime 4.1.1 Mozilla Netscape Portable Runtime 0 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Juniper CTPView 7.3 Juniper CTPView 7.1R2 Juniper CTPView 7.1r1 IBM TSSC 7.3.15 IBM TSSC 7.3 IBM TSSC 7.0 IBM SmartCloud Entry 3.2 IBM Security Network Protection (XGS) 5100 5.1.2 1 IBM Security Network Protection (XGS) 5100 5.1.2 IBM Security Network Protection (XGS) 5100 5.1.1 IBM Security Network Protection (XGS) 5100 5.2 IBM Security Network Protection (XGS) 5100 5.1 IBM Security Network Protection (XGS) 4100 5.1.2 1 IBM Security Network Protection (XGS) 4100 5.1.2 IBM Security Network Protection (XGS) 4100 5.1.1 IBM Security Network Protection (XGS) 4100 5.2 IBM Security Network Protection (XGS) 4100 5.1 IBM Security Network Protection (XGS) 3100 5.1.2 1 IBM Security Network Protection (XGS) 3100 5.1.2 IBM Security Network Protection (XGS) 3100 5.1.1 IBM Security Network Protection (XGS) 3100 5.2 IBM Security Network Protection (XGS) 3100 5.1 IBM FlashSystem 840 9848G-AC0 IBM FlashSystem 840 9848-AE1 IBM FlashSystem 840 9846G-AC0 IBM FlashSystem 840 9846-AE1 IBM FlashSystem 840 9843-AE1 IBM FlashSystem 840 9840-AE1 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 CentOS CentOS 6 CentOS CentOS 5 |
| Not Vulnerable: |
Mozilla Netscape Portable Runtime 4.10.6 Juniper CTPView 7.3R1 Juniper CTPView 7.1R3 IBM TSSC 7.3.16 IBM SmartCloud Entry 3.2.0.4 |
Discussion
Mozilla Netscape Portable Runtime CVE-2014-1545 Out of Bounds Memory Corruption Vulnerability
Mozilla Netscape Portable Runtime is prone to to a memory-corruption vulnerability.
Successful exploits may allow an attacker to execute arbitrary code in the context of the user running the affected application or result in denial-of-service conditions.
Versions prior to Netscape Portable Runtime 4.10.6 are vulnerable.
Mozilla Netscape Portable Runtime is prone to to a memory-corruption vulnerability.
Successful exploits may allow an attacker to execute arbitrary code in the context of the user running the affected application or result in denial-of-service conditions.
Versions prior to Netscape Portable Runtime 4.10.6 are vulnerable.
Exploit / POC
Mozilla Netscape Portable Runtime CVE-2014-1545 Out of Bounds Memory Corruption Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Mozilla Netscape Portable Runtime CVE-2014-1545 Out of Bounds Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
MandrakeSoft Enterprise Server 5 x86_64
Solution:
Updates are available. Please see the references or vendor advisory for more information.
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva lib64nspr-devel-4.10.6-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64nspr4-4.10.6-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64nss-devel-3.16.1-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64nss-static-devel-3.16.1-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64nss3-3.16.1-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva nss-3.16.1-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva nss-doc-3.16.1-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva rootcerts-20140401.00-1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva rootcerts-java-20140401.00-1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
Mozilla Netscape Portable Runtime CVE-2014-1545 Out of Bounds Memory Corruption Vulnerability
References:
References:
- Mozilla Homepage (Mozilla Foundation)
- Netscape Portable Runtime API Home Page (Mozilla)
- Security Bulletin: IBM Security Network Protection is affected by multiple vulne (IBM)
- TS3000 code level 7.x affected by various vulnerabilities (IBM)
- 2016-10 Security Bulletin: CTPView: Multiple vulnerabilities in CTPView (Juniper)
- Mozilla Foundation Security Advisory 2014-55 (Mozilla)
- Oracle VM Server for x86 Bulletin - July 2016 (Oracle)
- Security Bulletin: IBM SmartCloud Entry - 2 issues in NSS and NSPR (CVE-2014-154 (IBM)
- Six (6) Vulnerabilities in Network Security Services (NSS) & Netscape Portable R (IBM)