---
title: "CVE-2014-1544\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2014-1544?format=md
keywords: index, follow
---

# CVE-2014-1544

Publication date 22 July 2014

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Use-after-free vulnerability in the CERT\_DestroyCertificate function in
libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in
Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before
24.7, allows remote attackers to execute arbitrary code via vectors that
trigger certain improper removal of an NSSCertificate structure from a
trust domain.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| firefox | 14.04 LTS trusty | Fixed 31.0+build1-0ubuntu0.14.04.1 |
| 12.04 LTS precise | Fixed 31.0+build1-0ubuntu0.12.04.1 |
| 10.04 LTS lucid | Ignored end of life |
| nss | 14.04 LTS trusty | Fixed 2:3.15.4-1ubuntu7.1 |
| 12.04 LTS precise | Fixed 3.15.4-0ubuntu0.12.04.3 |
| 10.04 LTS lucid | Fixed 3.15.4-0ubuntu0.10.04.3 |
| thunderbird | 14.04 LTS trusty | Fixed 1:31.0+build1-0ubuntu0.14.04.1 |
| 12.04 LTS precise | Fixed 1:31.0+build1-0ubuntu0.12.04.1 |
| 10.04 LTS lucid | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2014-1544?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| nss | * Upstream:   <https://hg.mozilla.org/projects/nss/rev/204f22c527f8> * Upstream:   <https://hg.mozilla.org/projects/nss/rev/872dd4d243ac> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1544)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2014-1544)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2014-1544)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2014-1544)

### Related Ubuntu Security Notices (USN)

+ [USN-2296-1](https://usn.ubuntu.com/USN-2296-1)
+ Thunderbird vulnerabilities
+ 22 July 2014

+ [USN-2343-1](https://usn.ubuntu.com/USN-2343-1)
+ NSS vulnerability
+ 9 September 2014

+ [USN-2295-1](https://usn.ubuntu.com/USN-2295-1)
+ Firefox vulnerabilities
+ 22 July 2014

### Other references

* <https://www.mozilla.org/security/announce/2014/mfsa2014-63.html>
* <https://www.cve.org/CVERecord?id=CVE-2014-1544>
