Multiple Mozilla products contain a flaw in the ASN.1 decoder in the QuickDER decoder of Mozilla Network Security Services that may allow a remote denial of service. The issue is triggered when handling a zero-length basic constraint or a zero-length field in an OCSP response. This will result in a loss of availability for the program.
Classification
Location:
Remote / Network Access
Attack Type:
Denial of Service
Impact:
Loss of Availability
Solution:
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified,
Coordinated Disclosure
OSVDB:
Web Related
Solution
Upgrade Firefox or Thunderbird to version 13 or 10.0.5 for ESR, SeaMonkey to version 2.10 or higher, and Network Security Services to version 3.13.4 or higher, as they have been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.