Описание
Improper refcounting of soft token session objects could cause a use-after-free and crash (likely limited to a denial of service). This vulnerability affects Firefox < 71.
A use-after-free flaw was found in Mozilla Network Security Services (NSS) related to PK11 session handling. An attacker could use this flaw to execute arbitrary code with the permissions of the user running the application compiled with NSS.
Отчет
This flaw was fixed in upstream nss-3.47. Exploitation of this flaw is difficult and even impossible in most cases.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | nss | Out of support scope | ||
| Red Hat Enterprise Linux 6 | nss | Out of support scope | ||
| Red Hat Enterprise Linux 7 | nspr | Fixed | RHSA-2020:4076 | 29.09.2020 |
| Red Hat Enterprise Linux 7 | nss | Fixed | RHSA-2020:4076 | 29.09.2020 |
| Red Hat Enterprise Linux 7 | nss-softokn | Fixed | RHSA-2020:4076 | 29.09.2020 |
| Red Hat Enterprise Linux 7 | nss-util | Fixed | RHSA-2020:4076 | 29.09.2020 |
| Red Hat Enterprise Linux 7.4 Advanced Update Support | nss-softokn | Fixed | RHSA-2021:0758 | 09.03.2021 |
| Red Hat Enterprise Linux 7.4 Telco Extended Update Support | nss-softokn | Fixed | RHSA-2021:0758 | 09.03.2021 |
| Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions | nss-softokn | Fixed | RHSA-2021:0758 | 09.03.2021 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | nss | Fixed | RHSA-2021:0876 | 16.03.2021 |
Показывать по
Дополнительная информация
Статус:
7.1 High
CVSS3
Связанные уязвимости
Improper refcounting of soft token session objects could cause a use-after-free and crash (likely limited to a denial of service). This vulnerability affects Firefox < 71.
Improper refcounting of soft token session objects could cause a use-after-free and crash (likely limited to a denial of service). This vulnerability affects Firefox < 71.
Improper refcounting of soft token session objects could cause a use-a ...
Improper refcounting of soft token session objects could cause a use-after-free and crash (likely limited to a denial of service). This vulnerability affects Firefox < 71.
Уязвимость компонента перерасчета объектов сеанса веб-браузера Firefox, связанная с обращение к освобожденному участку памяти, позволяющая нарушителю получить несанкционированный доступ к конфиденциальным данным, вызвать отказ в обслуживании и оказать воздействие на целостность данных
7.1 High
CVSS3