Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-18508

Опубликовано: 22 янв. 2019
Источник: redhat
CVSS3: 6.5

Описание

In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service.

Меры по смягчению последствий

This issue only affects applications compiled against NSS which use CMS (Cryptographic Message Syntax) API. Other applications are not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5nssWill not fix
Red Hat Enterprise Linux 6nssWill not fix
Red Hat Enterprise Linux 7nssWill not fix
Red Hat Enterprise Linux 8mingw-nssWill not fix
Red Hat Virtualization 4redhat-virtualization-hostWill not fix
Red Hat Virtualization 4rhvm-applianceWill not fix
Red Hat Enterprise Linux 8nsprFixedRHSA-2019:195130.07.2019
Red Hat Enterprise Linux 8nssFixedRHSA-2019:195130.07.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1671310nss: NULL pointer dereference in several CMS functions resulting in a denial of service

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 5 лет назад

In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service.

CVSS3: 6.5
nvd
около 5 лет назад

In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service.

CVSS3: 6.5
debian
около 5 лет назад

In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a ...

github
больше 3 лет назад

In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service.

CVSS3: 6.5
fstec
почти 7 лет назад

Уязвимость компонента Сertificate Management Server набора библиотек Network Security Services, позволяющая нарушителю вызвать отказ в обслуживании

6.5 Medium

CVSS3