Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-17006

Опубликовано: 22 окт. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 10
CVSS3: 9.8

Описание

In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.

РелизСтатусПримечание
bionic

released

2:3.35-2ubuntu2.7
devel

not-affected

2:3.47-1ubuntu2
disco

released

2:3.42-1ubuntu2.5
eoan

released

2:3.45-1ubuntu2.2
esm-infra-legacy/trusty

released

2:3.28.4-0ubuntu0.14.04.5+esm4
esm-infra/bionic

released

2:3.35-2ubuntu2.7
esm-infra/xenial

released

2:3.28.4-0ubuntu0.16.04.10
precise/esm

not-affected

2:3.28.4-0ubuntu0.12.04.7
trusty

ignored

end of standard support
trusty/esm

released

2:3.28.4-0ubuntu0.14.04.5+esm4

Показывать по

EPSS

Процентиль: 80%
0.01458
Низкий

10 Critical

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.1
redhat
почти 6 лет назад

In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.

CVSS3: 9.8
nvd
около 5 лет назад

In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.

CVSS3: 9.8
debian
около 5 лет назад

In Network Security Services (NSS) before 3.46, several cryptographic ...

github
больше 3 лет назад

In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.

CVSS3: 8.1
fstec
почти 6 лет назад

Уязвимость набора библиотек NSS (Network Security Services), существующая из-за недостаточной проверки входных данных, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 80%
0.01458
Низкий

10 Critical

CVSS2

9.8 Critical

CVSS3