Netscape.SSLv2.Heap.Overflow

description-logoDescription

This indicates an attack attempt to exploit a heap-overflow vulnerability in Netscape SSL.
The Netscape Network Security Services (NSS) library is vulnerable to a heap-overflow attack. There is a flaw when handling modified record length fields in an SSLv2 client hello message which can be exploited by an attacker. A successful exploit can lead to the execution of arbitrary code and system compromise.

affected-products-logoAffected Products

Mozilla Network Security Services (NSS) 3.2 - 3.9
Netscape Certificate Server 1.0 P1
Netscape Certificate Server 4.2
Netscape Directory Server 1.3 P5
Netscape Directory Server 3.1 P1 4.13
Netscape Enterprise Server 2.0 - 4.1
Sun Java System Application Server 7.0 - 7.1
Sun ONE Web Server 4.1 - 6.2 SP2

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply appropriate patches from the following references:
Sun Java Enterprise System 2003Q4
* Sun 114045-12
Solaris 8 Sparc::
* Sun 114049-12
Solaris 9 Sparc::
* Sun 114050-12
Solaris 9 x86:
* Sun 115924-09
Solaris 8 Sparc:
* Sun 115926-10
Solaris 9 Sparc:
* Sun 115927-10
Solaris 9 x86
Mozilla Network Security Services (NSS) 3.2
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Mozilla Network Security Services (NSS) 3.2.1
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Mozilla Network Security Services (NSS) 3.3
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Mozilla Network Security Services (NSS) 3.3.2
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Mozilla Network Security Services (NSS) 3.4
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Mozilla Network Security Services (NSS) 3.5
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Mozilla Network Security Services (NSS) 3.6.1
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Mozilla Network Security Services (NSS) 3.7.2
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Mozilla Network Security Services (NSS) 3.7.3
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Mozilla Network Security Services (NSS) 3.7.5
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Mozilla Network Security Services (NSS) 3.7.7
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Mozilla Network Security Services (NSS) 3.8
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Mozilla Network Security Services (NSS) 3.9
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Sun Java System Application Server 7.0 Platform Edition
* Sun Sun Java System Application Server 7 2004Q2 Update 1:
* Sun Sun Java System Application Server Platform Edition 7 Update 5:

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2021-04-28 18.069 Sig Added