bug#61573: Arbitrary memory write vulnerability in NSS CVE-2023-0767

2023-02-21 Thread Maxim Cournoyer
Hi Leo, Leo Famulari writes: > There's a serious vulnerability in NSS: > > "An attacker could construct a PKCS 12 cert bundle in such a way that > could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes > being mishandled." > > https://www.mozilla.org/en-US/security/advisories/mf

bug#61573: Arbitrary memory write vulnerability in NSS CVE-2023-0767

2023-02-17 Thread Leo Famulari
There's a serious vulnerability in NSS: "An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mishandled." https://www.mozilla.org/en-US/security/advisories/mfsa2023-06/#CVE-2023-0767 Apparently it is f