Описание
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
Отчет
This issue was addressed via upstream nss-3.44, which is already shipped with Red Hat Enterprise Linux 6, 7 and 8.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform 6 | nss | Out of support scope | ||
| Red Hat Enterprise Linux 6 | nspr | Fixed | RHEA-2019:3280 | 31.10.2019 |
| Red Hat Enterprise Linux 6 | nss | Fixed | RHEA-2019:3280 | 31.10.2019 |
| Red Hat Enterprise Linux 6 | nss-softokn | Fixed | RHEA-2019:3280 | 31.10.2019 |
| Red Hat Enterprise Linux 6 | nss-util | Fixed | RHEA-2019:3280 | 31.10.2019 |
| Red Hat Enterprise Linux 7 | nspr | Fixed | RHSA-2019:2237 | 06.08.2019 |
| Red Hat Enterprise Linux 7 | nss | Fixed | RHSA-2019:2237 | 06.08.2019 |
| Red Hat Enterprise Linux 7 | nss-softokn | Fixed | RHSA-2019:2237 | 06.08.2019 |
| Red Hat Enterprise Linux 7 | nss-util | Fixed | RHSA-2019:2237 | 06.08.2019 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | nss | Fixed | RHSA-2021:0876 | 16.03.2021 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
In Network Security Services before 3.44, a malformed Netscape Certifi ...
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
Уязвимость набора криптографических библиотек NSS, связанная с неправильным подтверждением подлинности сертификата, позволяющая нарушителю вызвать отказ в обслуживании
7.5 High
CVSS3