Severity
9.8CRITICAL
EPSS
3.0%
top 13.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 22
Latest updateMay 24

Description

In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages11 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-h4cr-x49j-2r7w: In Network Security Services (NSS) before 32022-05-24
CVEList
CVE-2019-17006: In Network Security Services (NSS) before 32020-10-22
OSV
CVE-2019-17006: In Network Security Services (NSS) before 32020-10-22

📋Vendor Advisories

3
Ubuntu
NSS vulnerability2020-01-08
Red Hat
nss: Check length of inputs for cryptographic primitives2019-12-26
Debian
CVE-2019-17006: nss - In Network Security Services (NSS) before 3.46, several cryptographic primitives...2019

💬Community

1
Bugzilla
CVE-2019-17006 nss: Check length of inputs for cryptographic primitives2019-11-23
CVE-2019-17006 (CRITICAL CVSS 9.8) | In Network Security Services (NSS) | cvebase.io