RSS   Vulnerabilities for 'Nss esr'   RSS

2021-12-08
 
CVE-2021-43527

CWE-787
 

 
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS < 3.73 and NSS < 3.68.1.

 

 >>> Vendor: Mozilla 30 Products
Bugzilla
Mozilla
Firefox
Seamonkey
Thunderbird
Bonsai
Network security services
Camino
Mozilla suite
Durian web application server
Geckb
Libxul
NSS
Gecko
Firefox esr
Thunderbird esr
Firefox mobile
Zamboni
Firef14caox
Netscape portable runtime
Firefoxos
Firefox os
Bleach
Nunjucks
Mozjpeg
Webthings gateway
Pollbot
Hubs cloud reticulum
Mozilla vpn
Nss esr


Copyright 2022, cxsecurity.com

 

Back to Top