Back

HIGH

nss: Race-condition in certificate verification can lead to Remote code execution (MFSA 2014-63)

Published Jul 23, 2014

Description

Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a trust domain.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (20)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Jul 23, 2014
Updated Aug 6, 2024
Reserved Jan 16, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Jul 22, 2014