CVE-2013-1739

medium
Published 2013-10-22 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.0

Description

Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker ยท View original โ†— ยท DFSG

CVE-2013-1739 NameCVE-2013-1739 DescriptionMozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat,โ€ฆ

CVE-2013-1739

NameCVE-2013-1739
DescriptionMozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-2790-1
Debian Bugs726473

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nss (PTS)bullseye2:3.61-1+deb11u3fixed
bullseye (security)2:3.61-1+deb11u5fixed
bookworm, bookworm (security)2:3.87.1-1+deb12u2fixed
trixie2:3.110-1+deb13u1fixed
trixie (security)2:3.110-1+deb13u2fixed
forky, sid2:3.124-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nsssourcesqueeze(not affected)
nsssourcewheezy2:3.14.4-1DSA-2790-1
nsssource(unstable)2:3.15.2-1726473

Notes

[squeeze] - nss <not-affected> (Introduced in 3.14.3)
https://developer.mozilla.org/en-US/docs/NSS/NSS_3.15.2_release_notes
https://bugzilla.redhat.com/show_bug.cgi?id=1012656

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[squeeze] - nss <not-affected> (Introduced in 3.14.3)https://developer.mozilla.org/en-US/docs/NSS/NSS_3.15.2_release_noteshttps://bugzilla.redhat.com/show_bug.cgi?id=1012656

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2:3.15.2-1
debian debianbullseyefixed2:3.15.2-1
debian debianforkyfixed2:3.15.2-1
debian debiansidfixed2:3.15.2-1
debian debiantrixiefixed2:3.15.2-1

Application impact

VendorProductVersionsFixed
mozilla mozillanetwork_security_services{"endIncluding":"3.15.1"}
mozilla mozillanetwork_security_services3.12
mozilla mozillanetwork_security_services3.12.1
mozilla mozillanetwork_security_services3.12.2
mozilla mozillanetwork_security_services3.12.3
mozilla mozillanetwork_security_services3.12.3.1
mozilla mozillanetwork_security_services3.12.3.2
mozilla mozillanetwork_security_services3.12.4
mozilla mozillanetwork_security_services3.12.5
mozilla mozillanetwork_security_services3.12.6
mozilla mozillanetwork_security_services3.12.7
mozilla mozillanetwork_security_services3.12.8
mozilla mozillanetwork_security_services3.12.9
mozilla mozillanetwork_security_services3.12.10
mozilla mozillanetwork_security_services3.12.11
mozilla mozillanetwork_security_services3.14
mozilla mozillanetwork_security_services3.14.1
mozilla mozillanetwork_security_services3.14.2
mozilla mozillanetwork_security_services3.14.3
mozilla mozillanetwork_security_services3.15

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.