Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-17006

Опубликовано: 22 окт. 2020
Источник: debian
EPSS Низкий

Описание

In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nssfixed2:3.47-1package

Примечания

  • Fixed upstream in NSS 3.46.

  • Upstream bug (currently non-public): https://bugzilla.mozilla.org/show_bug.cgi?id=1539788

  • https://hg.mozilla.org/projects/nss/rev/dfd6996fe7425eb0437346d11a01082f16fcfe34

  • https://hg.mozilla.org/projects/nss/rev/9d1f5e71773d4e3146524096d74cb96c8df51abe

EPSS

Процентиль: 80%
0.01458
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 5 лет назад

In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.

CVSS3: 8.1
redhat
почти 6 лет назад

In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.

CVSS3: 9.8
nvd
около 5 лет назад

In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.

github
больше 3 лет назад

In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.

CVSS3: 8.1
fstec
почти 6 лет назад

Уязвимость набора библиотек NSS (Network Security Services), существующая из-за недостаточной проверки входных данных, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 80%
0.01458
Низкий