CVE-2019-17006
published 2020-10-22CVE-2019-17006: In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library…
PriorityP351critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.60%
88.1th percentile
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nss | < nss 2:3.47-1 (bookworm) | nss 2:3.47-1 (bookworm) |
| mozilla | network_security_services | < 3.46 | 3.46 |
| mozilla | nss | >= 0 < 2:3.47-1 | 2:3.47-1 |
| mozilla | nss | >= 0 < 2:3.47-1 | 2:3.47-1 |
| mozilla | nss | >= 0 < 2:3.47-1 | 2:3.47-1 |
| mozilla | nss | >= 0 < 2:3.47-1 | 2:3.47-1 |
| mozilla | nss | >= unspecified < 3.46 | 3.46 |
| paloalto | pan-os | — | — |
| siemens | ruggedcom_rox_mx5000_firmware | < 2.14.0 | 2.14.0 |
| siemens | ruggedcom_rox_rx1400_firmware | < 2.14.0 | 2.14.0 |
| siemens | ruggedcom_rox_rx1500_firmware | < 2.14.0 | 2.14.0 |
| siemens | ruggedcom_rox_rx1501_firmware | < 2.14.0 | 2.14.0 |
| siemens | ruggedcom_rox_rx1510_firmware | < 2.14.0 | 2.14.0 |
| siemens | ruggedcom_rox_rx1511_firmware | < 2.14.0 | 2.14.0 |
| siemens | ruggedcom_rox_rx1512_firmware | < 2.14.0 | 2.14.0 |
| siemens | ruggedcom_rox_rx5000_firmware | < 2.14.0 | 2.14.0 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
vendor_paloalto·2024-10-29·CVSS 9.8
CVE-2019-17006 [CRITICAL] PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2019-17006 This CVE is fixed in PAN-OS 10.2.0, and all later versions of PAN-OS. CVE-2021-3518 This CVE is fixed in PAN-OS 10.2.0, and all later versions of PAN-OS. CVE-2021-25219 This CVE is fixed in PAN-OS 10.2.3, and all later versions of PAN-OS. CVE-2021-27645 This CVE is fixed in PAN-OS 10.2.8, PAN-OS 11.0.2, and all later versions of PAN-OS. CVE-2021-34798 This CVE is fixed in PAN-OS 10.2.8, PAN-OS 11.0.2, and all later versions o
CISA ICS
Siemens RUGGEDCOM ROX II
cisa_ics·2021-02-09·CVSS 5.9
[MEDIUM] Siemens RUGGEDCOM ROX II
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens RUGGEDCOM ROX II
Last RevisedFebruary 09, 2021
Alert CodeICSA-21-040-04
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Siemens
- Equipment: RUGGEDCOM ROX IIB
- Vulnerabilities: Improper Input Validation, NULL Pointer Dereference, Out-of-Bounds Write, Insufficient Verification of Data Authenticity, Improper Certificate Validation, Out-of-bounds Read
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow the decryption of encrypted content, possible code execution, or cause a sy
Ubuntu
NSS vulnerability
vendor_ubuntu·2020-01-08
CVE-2019-17006 NSS vulnerability
Title: NSS vulnerability
Summary: NSS could be made to execute arbitrary code if it received a specially
crafted input.
It was discovered that NSS incorrectly handled certain inputs. An
attacker could possibly use this issue to execute arbitrary code.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
nss: Check length of inputs for cryptographic primitives
vendor_redhat·2019-12-26·CVSS 9.8
CVE-2019-17006 [CRITICAL] CWE-122 nss: Check length of inputs for cryptographic primitives
nss: Check length of inputs for cryptographic primitives
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.
A vulnerability was discovered in nss where input text length was not checked when using certain cryptographic primitives. This could lead to a heap-buffer overflow resulting in a crash and data leak. The highest threat is to confidentiality and integrity of data as well as system availability.
Package: nss (Red Hat Enterprise Linux 6) - Out of support scope
Debian
CVE-2019-17006: nss - In Network Security Services (NSS) before 3.46, several cryptographic primitives...
vendor_debian·2019·CVSS 9.8
CVE-2019-17006 [CRITICAL] CVE-2019-17006: nss - In Network Security Services (NSS) before 3.46, several cryptographic primitives...
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.
Scope: local
bookworm: resolved (fixed in 2:3.47-1)
bullseye: resolved (fixed in 2:3.47-1)
forky: resolved (fixed in 2:3.47-1)
sid: resolved (fixed in 2:3.47-1)
trixie: resolved (fixed in 2:3.47-1)
GHSA
GHSA-h4cr-x49j-2r7w: In Network Security Services (NSS) before 3
ghsa_unreviewed·2022-05-24
CVE-2019-17006 [CRITICAL] CWE-345 GHSA-h4cr-x49j-2r7w: In Network Security Services (NSS) before 3
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.
OSV
CVE-2019-17006: In Network Security Services (NSS) before 3
osv·2020-10-22·CVSS 9.8
CVE-2019-17006 [CRITICAL] CVE-2019-17006: In Network Security Services (NSS) before 3
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.
No detection rules found.
No public exploits indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1539788https://cert-portal.siemens.com/productcert/pdf/ssa-379803.pdfhttps://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.46_release_noteshttps://security.netapp.com/advisory/ntap-20210129-0001/https://us-cert.cisa.gov/ics/advisories/icsa-21-040-04https://bugzilla.mozilla.org/show_bug.cgi?id=1539788https://cert-portal.siemens.com/productcert/pdf/ssa-379803.pdfhttps://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.46_release_noteshttps://security.netapp.com/advisory/ntap-20210129-0001/https://us-cert.cisa.gov/ics/advisories/icsa-21-040-04
2020-10-22
Published