[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3998-1 nss -- nss

ID: oval:org.secpod.oval:def:603127Date: (C)2017-10-13   (M)2023-12-20
Class: PATCHFamily: unix




Martin Thomson discovered that nss, the Mozilla Network Security Service library, is prone to a use-after-free vulnerability in the TLS 1.2 implementation when handshake hashes are generated. A remote attacker can take advantage of this flaw to cause an application using the nss library to crash, resulting in a denial of service, or potentially to execute arbitrary code.

Platform:
Debian 8.x
Debian 9.x
Product:
libnss3
Reference:
DSA-3998-1
CVE-2017-7805
CVE    1
CVE-2017-7805
CPE    6
cpe:/o:debian:debian_linux:9.0
cpe:/a:mozilla:libnss3
cpe:/o:debian:debian_linux:8.x
cpe:/o:debian:debian_linux:9.x
...

© SecPod Technologies