CVE-2007-0008
Firefox < 1.5.0.10 and 2.x < 2.0.0.2 - Remote Code Execution via SSLv2 Public Key Underflow
Title source: llmDescription
Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via a crafted SSLv2 server message containing a public key that is too short to encrypt the "Master Secret", which results in a heap-based overflow.
References (74)
Core 74
Core References
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2007-0078.html
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24562
Third Party Advisory vendor-advisory
x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200703-22.xml
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24703
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24395
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/461336/100/0/threaded
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24328
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2007-0108.html
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24277
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24252
Vendor Advisory vendor-advisory
x_refsource_slackware
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.374851
Vendor Advisory vendor-advisory
x_refsource_slackware
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.363947
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/25597
Mailing List vendor-advisory
x_refsource_fedora
http://fedoranews.org/cms/node/2709
Mailing List vendor-advisory
x_refsource_fedora
http://fedoranews.org/cms/node/2747
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24384
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24406
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24457
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24253
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2007:052
Vendor Advisory x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=364319
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24343
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2007/dsa-1336
Vendor Advisory vendor-advisory
x_refsource_hp
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1165
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1017696
Vendor Advisory vendor-advisory
x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102945-1
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2007/0718
Mailing List vendor-advisory
x_refsource_fedora
http://fedoranews.org/cms/node/2711
Mailing List vendor-advisory
x_refsource_fedora
http://fedoranews.org/cms/node/2749
Third Party Advisory vendor-advisory
x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200703-18.xml
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24650
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-428-1
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24320
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/25588
Issue Tracking x_refsource_confirm
https://issues.rpath.com/browse/RPL-1103
Various Sources vendor-advisory
x_refsource_suse
http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/461809/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/32105
Vendor Advisory vendor-advisory
x_refsource_suse
http://www.novell.com/linux/security/advisories/2007_22_mozilla.html
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24293
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24238
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24456
Patch, Vendor Advisory x_refsource_confirm
http://www.mozilla.org/security/announce/2007/mfsa2007-06.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24342
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24287
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24522
Vendor Advisory vendor-advisory
x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102856-1
Vendor Advisory third-party-advisory
x_refsource_idefense
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=482
US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/377812
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/22694
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2007/0719
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/32666
Mailing List vendor-advisory
x_refsource_fedora
http://fedoranews.org/cms/node/2713
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-431-1
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2007-0097.html
Mailing List vendor-advisory
x_refsource_fedora
http://fedoranews.org/cms/node/2728
Vendor Advisory vendor-advisory
x_refsource_sgi
ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10502
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24205
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24389
Issue Tracking x_refsource_confirm
https://issues.rpath.com/browse/RPL-1081
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24410
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24333
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2141
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2007:050
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/64758
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24290
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24455
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2007-0077.html
Vendor Advisory vendor-advisory
x_refsource_sgi
ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc
Vendor Advisory x_refsource_confirm
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
Vendor Advisory vendor-advisory
x_refsource_slackware
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2007-0079.html
Scores
EPSS
0.0433
EPSS Percentile
90.1%
Details
CWE
CWE-189
Status
published
Products (48)
mozilla/firefox
0.1
mozilla/firefox
0.2
mozilla/firefox
0.3
mozilla/firefox
0.4
mozilla/firefox
0.5
mozilla/firefox
0.6
mozilla/firefox
0.6.1
mozilla/firefox
0.7
mozilla/firefox
0.7.1
mozilla/firefox
0.8
... and 38 more
Published
Feb 26, 2007
Tracked Since
Feb 18, 2026