CVE-2013-0791: Canonical Ubuntu Linux
Medium severity, CVSS 5.0. EPSS: 5.2% chance of exploitation in the next 30 days.
The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted certificate.
Affected products
- Canonical Ubuntu Linux: version 10.04 only; version 11.10 only; version 12.04 only; version 12.10 only
- Mozilla Firefox: up to and including 20.0; from 17.0, before 17.0.5 (fixed in 17.0.5)
- Mozilla Network Security Services: before 3.15 (fixed in 3.15)
- Mozilla Seamonkey: before 2.17 (fixed in 2.17)
- Mozilla Thunderbird: before 17.0.5 (fixed in 17.0.5)
- Mozilla Thunderbird ESR: from 17.0, before 17.0.5 (fixed in 17.0.5)
- Oracle Vm Server: version 3.2 only
- Red Hat Enterprise Linux Desktop: version 5.0 only; version 6.0 only
- Red Hat Enterprise Linux Eus: version 5.9 only
- Red Hat Enterprise Linux Server: version 5.0 only; version 6.0 only
- Red Hat Enterprise Linux Server Aus: version 5.9 only
- Red Hat Enterprise Linux Workstation: version 5.0 only; version 6.0 only
Published 2013-04-03. Last modified 2026-06-16.