Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Ubuntu 13.10: 2087-1 Critical NSPR Denial Of Service Attack

ubuntu
Calendar Grey January 23, 2014
Scroller Ubuntu
Uncover the significant NSPR flaw in Ubuntu impacting various editions. Address it promptly through system updates.
NSPR could be made to crash or run programs if it received a specially crafted certificate.

Summary

NSPR could be made to crash or run programs if it received a specially

crafted certificate.

Software Description:

- nspr: NetScape Portable Runtime Library

Details:

It was discovered that NSPR incorrectly handled certain malformed X.509

certificates. A remote attacker could use a crafted X.509 certificate to

cause NSPR to crash, leading to a denial of service, or possibly execute

arbitrary code.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  libnspr4                        2:4.9.5-1ubuntu1.1

Ubuntu 12.10:
  libnspr4                        4.9.5-0ubuntu0.12.10.2

Ubuntu 12.04 LTS:
  libnspr4                        4.9.5-0ubuntu0.12.04.2

Ubuntu 10.04 LTS:
  libnspr4-0d                     4.9.5-0ubuntu0.10.04.2

After a standard system update you need to restart your session to make
all the necessary changes.

References

CVE-2013-5607

Severity
critical
Lowest
Low
Medium
High
Critical

January 23, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.