CVE Database
/

CVE-2012-0441

Back to search

CVE-2012-0441

Published: Jun 5, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (NSS) before 3.13.4, as used in Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10, allows remote attackers to cause a denial of service (application crash) via a zero-length item, as demonstrated by (1) a zero-length basic constraint or (2) a zero-length field in an OCSP response.

VendorProductVersions

n/a

n/a

affected
n/a

References

49976
third-party-advisory
x_refsource_SECUNIA
USN-1540-2
vendor-advisory
x_refsource_UBUNTU
MDVSA-2012:088
vendor-advisory
x_refsource_MANDRIVA
oval:org.mitre.oval:def:16701
vdb-entry
signature
x_refsource_OVAL
53798
vdb-entry
x_refsource_BID
DSA-2490
vendor-advisory
x_refsource_DEBIAN
SUSE-SU-2012:0746
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2012:0760
vendor-advisory
x_refsource_SUSE
50316
third-party-advisory
x_refsource_SECUNIA
USN-1540-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now