Bugzilla – Bug 970257
VUL-0: CVE-2016-1950: mozilla-nss: Heap buffer overflow vulnerability in ASN1 certificate parsing (MFSA 2016-35)
Last modified: 2019-05-01 17:05:32 UTC
rh#1310509 A heap-based buffer overflow was found in the ASN.1 parsing code of NSS. A remote attacker could create a specially-crafted certificate, which when parsed by NSS, could the application linked with NSS to crash or potentially execute code with the permission of the user running such an application. Applications such as web browsers which parse untrusted web content are specially vulnerable to this issue. References: https://bugzilla.redhat.com/show_bug.cgi?id=1310509 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-1950 http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-1950.html
updates were tracked in bug 969894 *** This bug has been marked as a duplicate of bug 969894 ***