Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Tue, 25 Oct 2011 10:32:56 -0400 (EDT)
From: Josh Bressers <bressers@...hat.com>
To: oss-security@...ts.openwall.com
Cc: Elio Maldonado <emaldona@...hat.com>, Robert Relyea <rrelyea@...hat.com>,
        "Steven M. Christey" <coley@...us.mitre.org>,
        Reed Loden <reed@...dloden.com>
Subject: Re: CVE Request -- nss: Did honour /pkcs11.txt and /secmod.db files by initialization

Reed asked me to give this a CVE id.

Please use CVE-2011-3640

Thanks.

-- 
    JB

----- Original Message -----
> Hello Josh, Steve, vendors,
> 
>    a security flaw was found in the way nss, the Network Security
> Services (NSS) set of libraries, performed their initialization (the
> file path for "pkcs11.txt" configuration file was constructed
> incorrectly). When that configuration file was loaded from remote
> WebDAV
> or Samba CIFS share, it could lead to arbitrary security module
> load, potentially leading to execution of arbitrary code (execution
> of
> code from untrusted security module).
> 
> Upstream bug report:
> [1] https://bugzilla.mozilla.org/show_bug.cgi?id=641052
> 
> Other references:
> [2] https://secunia.com/advisories/46557/
> [3] https://bugs.gentoo.org/show_bug.cgi?id=388045
> [4] http://code.google.com/p/chromium/issues/detail?id=97426#c8
> [5] https://bugzilla.redhat.com/show_bug.cgi?id=748379
> 
> Could you allocate a CVE id for this? (as it looks there isn't one
> for this deficiency yet)
> 
> Thank you && Regards, Jan.
> --
> Jan iankko Lieskovsky / Red Hat Security Response Team
> 

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.