Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messenger (AIM), allows remote SSL servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long domain name in the subject's Common Name (CN) field of an X.509 certificate, related to the cert_TestHostName function.

Project Subscriptions

Vendors Products
Instant Messenger Subscribe
Evolution Subscribe
Mozilla Subscribe
Firefox Subscribe
Network Security Services Subscribe
Seamonkey Subscribe
Thunderbird Subscribe
Enterprise Linux Subscribe
Rhel Eus Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-1874-1 New nss packages fix several vulnerabilities
Debian DSA Debian DSA DSA-2025-1 New icedove packages fix several vulnerabilities
Ubuntu USN Ubuntu USN USN-810-1 NSS vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://rhn.redhat.com/errata/RHSA-2009-1185.html cve-icon cve-icon
http://secunia.com/advisories/36088 cve-icon cve-icon
http://secunia.com/advisories/36102 cve-icon cve-icon
http://secunia.com/advisories/36125 cve-icon cve-icon
http://secunia.com/advisories/36139 cve-icon cve-icon
http://secunia.com/advisories/36157 cve-icon cve-icon
http://secunia.com/advisories/36434 cve-icon cve-icon
http://secunia.com/advisories/37098 cve-icon cve-icon
http://secunia.com/advisories/39428 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-66-273910-1 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021030.1-1 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021699.1-1 cve-icon cve-icon
http://www.blackhat.com/presentations/bh-usa-09/MARLINSPIKE/BHUSA09-Marlinspike-DefeatSSL-SLIDES.pdf cve-icon cve-icon
http://www.debian.org/security/2009/dsa-1874 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2009:197 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2009:216 cve-icon cve-icon
http://www.mozilla.org/security/announce/2009/mfsa2009-43.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2009_48_firefox.html cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/cpuapr2010-099504.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2009-1207.html cve-icon cve-icon
http://www.securityfocus.com/bid/35891 cve-icon cve-icon
http://www.ubuntu.com/usn/usn-810-1 cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA10-103B.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/2085 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=512912 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2009-2404 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11174 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8658 cve-icon cve-icon
https://usn.ubuntu.com/810-2/ cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2009-2404 cve-icon
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T05:52:14.939Z

Reserved: 2009-07-09T00:00:00

Link: CVE-2009-2404

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2009-08-03T14:30:00.610

Modified: 2025-04-09T00:30:58.490

Link: CVE-2009-2404

cve-icon Redhat

Severity : Critical

Publid Date: 2009-07-29T00:00:00Z

Links: CVE-2009-2404 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses