Netscape NSS Library Record Parsing Buffer Overflow
| Attack ID: | CPAI-2004-38 |
| Publish Date: | |
| Last Update: | |
| Category: | Netscape NSS Library Record Parsing Buffer Overflow |
| Vulnerable Systems: | Netscape Enterprise Webserver (All versions); Netscape Personalization Engine (All versions); Netscape Directory Server (All versions); Netscape Certificate Management Server (All versions); Sun Java Enterprise System (JES); Network Security Services (NSS) |
| Source: | CAN-2004-0826 |
| Description: | NSS is a set of open source crypto libraries which help implement and design cross platform applications that use SSL and S/MIME for encryption purposes. |
| Severity: | |
| A vulnerability exists in Netscape's Network Security Services SSL library when using SSL version 2 messages. A specially crafted "Client Hello" packet may cause the server to crash and possibly lead to remote code execution. | |
| Details: | A vulnerability exists in the SSL version 2 parsing engine of Netscape's Network Security Server. A "Client Hello" message request with an excessive challenge length (greater than 32 Bytes) leads to a buffer overflow. A malicious user may use this vulnerability and overwrite the heap with arbitrary data, which may lead to arbitrary remote code execution on the target machine and gain complete control over it, as the NSS service runs under Root privileges. |
| Attack Detection: | Using SmartView Tracker, users of VPN-1 NG with Application Intelligence R55 will be able to identify dropped logs with rule number 99443 displayed in the log viewer window. Users of VPN-1 NG with Application Intelligence R55W and InterSpect will receive the following logs: Attack name: VPN Protection (for all logs) |
| Solution: | Users of VPN-1 NG AI R55 and InterSpect should update their SmartDefense to the latest update by pressing the Update Now button in the SmartDefense General tab. This update includes an enhancement for the already existing SSL protections. To apply the protection (R55, R55W and InterSpect):
|
| Industry Reference: | |
| Additional Information: | SunSolve ID: 57643
|
