CVE Database
/

CVE-2009-2404

Back to search

CVE-2009-2404

Published: Aug 3, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messenger (AIM), allows remote SSL servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long domain name in the subject's Common Name (CN) field of an X.509 certificate, related to the cert_TestHostName function.

VendorProductVersions

n/a

n/a

affected
n/a

References

36139
third-party-advisory
x_refsource_SECUNIA
36102
third-party-advisory
x_refsource_SECUNIA
36157
third-party-advisory
x_refsource_SECUNIA
TA10-103B
third-party-advisory
x_refsource_CERT
oval:org.mitre.oval:def:11174
vdb-entry
signature
x_refsource_OVAL
MDVSA-2009:197
vendor-advisory
x_refsource_MANDRIVA
oval:org.mitre.oval:def:8658
vdb-entry
signature
x_refsource_OVAL
SUSE-SA:2009:048
vendor-advisory
x_refsource_SUSE
MDVSA-2009:216
vendor-advisory
x_refsource_MANDRIVA
RHSA-2009:1185
vendor-advisory
x_refsource_REDHAT
39428
third-party-advisory
x_refsource_SECUNIA
36434
third-party-advisory
x_refsource_SECUNIA
36088
third-party-advisory
x_refsource_SECUNIA
35891
vdb-entry
x_refsource_BID
RHSA-2009:1207
vendor-advisory
x_refsource_REDHAT
1021699
vendor-advisory
x_refsource_SUNALERT
USN-810-1
vendor-advisory
x_refsource_UBUNTU
USN-810-2
vendor-advisory
x_refsource_UBUNTU
1021030
vendor-advisory
x_refsource_SUNALERT
36125
third-party-advisory
x_refsource_SECUNIA
37098
third-party-advisory
x_refsource_SECUNIA
273910
vendor-advisory
x_refsource_SUNALERT
ADV-2009-2085
vdb-entry
x_refsource_VUPEN
DSA-1874
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now