Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-17006

Опубликовано: 22 окт. 2020
Источник: debian
EPSS Низкий

Описание

In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nssfixed2:3.47-1package

Примечания

  • Fixed upstream in NSS 3.46.

  • Upstream bug (currently non-public): https://bugzilla.mozilla.org/show_bug.cgi?id=1539788

  • https://hg.mozilla.org/projects/nss/rev/dfd6996fe7425eb0437346d11a01082f16fcfe34

  • https://hg.mozilla.org/projects/nss/rev/9d1f5e71773d4e3146524096d74cb96c8df51abe

EPSS

Процентиль: 86%
0.03036
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 5 лет назад

In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.

CVSS3: 8.1
redhat
около 6 лет назад

In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.

CVSS3: 9.8
nvd
больше 5 лет назад

In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.

github
больше 3 лет назад

In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.

CVSS3: 8.1
fstec
около 6 лет назад

Уязвимость набора библиотек NSS (Network Security Services), существующая из-за недостаточной проверки входных данных, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 86%
0.03036
Низкий