Endpoint Vulnerability

Crash due to handling of SSL on threads

Description

Mozilla community member Jerry Baker reported a crashing issue found through Thunderbird when downloading messages over a Secure Sockets Layer (SSL) connection. This was caused by a bug in the networking code assuming that secure connections were entirely handled on the socket transport thread when they can occur on a variety of threads. The resulting crash was potentially exploitable.

Affected Products

Firefox,Firefox ESR

References

CVE-2013-0764,