Back

HIGH

nss: Arbitrary memory write via PKCS 12

Published Jun 2, 2023

Description

An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mishandled. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

Affected products

Remediation

Red Hat statement

Firefox and Thunderbird in Red Hat Enterprise Linux 8.6 and later are not affected by this vulnerability, as they use the system NSS library. Firefox and Thunderbird in earlier Red Hat Enterprise Linux 8 extended life streams were affected, and should be updated to fixed versions as they become available.

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Jun 2, 2023
Updated May 5, 2025
Reserved Feb 9, 2023
CISA Vulnrichment
Updated Apr 23, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Feb 14, 2023
ENISA EUVD
Assigner mozilla
Published Jun 2, 2023
Updated May 5, 2025
Exploited since n/a
EUVD-2023-12784