The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (NSS) before 3.13.4, as used in Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10, allows remote attackers to cause a denial of service (application crash) via a zero-length item, as demonstrated by (1) a zero-length basic constraint or (2) a zero-length field in an OCSP response.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade nss | Aug 30, 2017 | Jun 5, 2012 |
| Centos_linux | — | Upgrade nss-pkcs11-develUpgrade nss-develUpgrade nss-sysinitUpgrade nss-utilUpgrade nsprUpgrade nssUpgrade nss-toolsUpgrade nspr-develUpgrade nss-util-devel | Dec 1, 2016 | Jun 5, 2012 |
| Debian | — | Upgrade nss | Jul 30, 2024 | Jun 5, 2012 |
| Freebsd | — | Upgrade libxulUpgrade seamonkeyUpgrade linux-firefoxUpgrade firefoxUpgrade linux-thunderbirdUpgrade linux-seamonkeyUpgrade thunderbird | Dec 10, 2025 | Jun 5, 2012 |
| Gentoo Linux | — | Upgrade mail-client/mozilla-thunderbird-bin.Upgrade mail-client/thunderbird-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade mail-client/thunderbird.Upgrade net-libs/xulrunner-bin.Upgrade www-client/firefox-bin.Upgrade www-client/seamonkey-bin.Upgrade net-libs/xulrunner.Upgrade www-client/firefox.Upgrade www-client/icecat.Upgrade www-client/seamonkey.Upgrade www-client/mozilla-firefox.Upgrade dev-libs/nss.Upgrade mail-client/mozilla-thunderbird. | Oct 30, 2017 | Jun 5, 2012 |
| Mfsa2012 39 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 13.0Upgrade to Mozilla Firefox ESR version 10.0.5 | Jun 14, 2012 | Jun 5, 2012 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.10.0 | Jun 19, 2012 | Jun 5, 2012 |
| Mozilla Thunderbird | — | Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 13.0Upgrade to Mozilla Thunderbird ESR version 10.0.5 | Jun 19, 2012 | Jun 5, 2012 |
| Oracle_linux | — | Upgrade nspr-develUpgrade nss-utilUpgrade nss-toolsUpgrade nss-develUpgrade nss-sysinitUpgrade nssUpgrade nsprUpgrade nss-pkcs11-develUpgrade nss-util-devel | Oct 16, 2024 | Jun 5, 2012 |
| Suse | — | Upgrade MozillaThunderbird-develUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-translationsUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefoxUpgrade MozillaThunderbirdUpgrade MozillaThunderbird-translations-commonUpgrade MozillaThunderbird-translations-otherUpgrade MozillaFirefox-devel | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libnss3-1dUpgrade firefoxUpgrade libnss3Upgrade thunderbird | Nov 8, 2024 | Jun 5, 2012 |
| Vmsa 2012 0016 | — | Upgrade VMware ESX 4.1 to build number 874690 | Nov 22, 2012 | Jun 5, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub