CVE-2009-2404
CVE-2009-2404
Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messenger (AIM), allows remote SSL servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long domain name in the subject's Common Name (CN) field of an X.509 certificate, related to the cert_TestHostName function.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://rhn.redhat.com/errata/RHSA-2009-1185.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=512912http://secunia.com/advisories/36088http://secunia.com/advisories/36102http://secunia.com/advisories/36125http://secunia.com/advisories/36139http://secunia.com/advisories/36157http://secunia.com/advisories/36434http://secunia.com/advisories/37098http://secunia.com/advisories/39428https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11174https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8658