[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2023-1942 --- nss-util

Deprecated
ID: oval:org.secpod.oval:def:1701170Date: (C)2023-02-24   (M)2024-04-17
Class: PATCHFamily: unix




Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memory and used. This vulnerability affects Firefox ESR less than 60.8, Firefox less than 68, and Thunderbird less than 60.8. A heap-based buffer overflow was found in the NSC_EncryptUpdate function in Mozilla nss. A remote attacker could trigger this flaw via SRTP encrypt or decrypt operations, to execute arbitrary code with the permissions of the user running the application . While the attack complexity is high, the impact to confidentiality, integrity, and availability are high as well

Platform:
Amazon Linux 2
Product:
nss-util
Reference:
ALAS2-2023-1942
CVE-2019-11729
CVE-2019-11745
CVE    2
CVE-2019-11729
CVE-2019-11745

© SecPod Technologies