An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mishandled. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8..This CVE has a CVSS3.1 score of 4.7 and a Base Severity of MEDIUM.
Info | Details |
---|---|
CVE ID | CVE-2023-0767 |
CVE State | PUBLISHED |
BaseScore | NA |
BaseSeverity | NA |
VectorString | NA |
Version | NA |
References for CVE-2023-0767 :
https://www.mozilla.org/security/advisories/mfsa2023-06/
https://www.mozilla.org/security/advisories/mfsa2023-05/
https://www.mozilla.org/security/advisories/mfsa2023-07/
https://bugzilla.mozilla.org/show_bug.cgi?id=1804640
https://alas.aws.amazon.com/AL2/ALAS-2023-1992.html
Metric Type | Metric Score |
---|---|
AttackVector(AV) | NA |
AttackComplexity(AC) | NA |
PrivilegesRequired(PR) | NA |
UserInteraction(UI) | NA |
Scope(S) | NA |
Confidentiality(C) | NA |
Availability(A) | NA |
Integrity(I) | NA |