CVE-2019-17007
published 2020-10-22CVE-2019-17007: In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.38%
69.1th percentile
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nss | < nss 2:3.45-1 (bookworm) | nss 2:3.45-1 (bookworm) |
| mozilla | network_security_services | < 3.44 | 3.44 |
| mozilla | nss | >= 0 < 2:3.45-1 | 2:3.45-1 |
| mozilla | nss | >= 0 < 2:3.45-1 | 2:3.45-1 |
| mozilla | nss | >= 0 < 2:3.45-1 | 2:3.45-1 |
| mozilla | nss | >= 0 < 2:3.45-1 | 2:3.45-1 |
| mozilla | nss | >= unspecified < 3.44 | 3.44 |
| siemens | ruggedcom_rox_mx5000_firmware | < 2.14.0 | 2.14.0 |
| siemens | ruggedcom_rox_rx1400_firmware | < 2.14.0 | 2.14.0 |
| siemens | ruggedcom_rox_rx1500_firmware | < 2.14.0 | 2.14.0 |
| siemens | ruggedcom_rox_rx1501_firmware | < 2.14.0 | 2.14.0 |
| siemens | ruggedcom_rox_rx1510_firmware | < 2.14.0 | 2.14.0 |
| siemens | ruggedcom_rox_rx1511_firmware | < 2.14.0 | 2.14.0 |
| siemens | ruggedcom_rox_rx1512_firmware | < 2.14.0 | 2.14.0 |
| siemens | ruggedcom_rox_rx5000_firmware | < 2.14.0 | 2.14.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens RUGGEDCOM ROX II
cisa_ics·2021-02-09·CVSS 5.9
[MEDIUM] Siemens RUGGEDCOM ROX II
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens RUGGEDCOM ROX II
Last RevisedFebruary 09, 2021
Alert CodeICSA-21-040-04
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Siemens
- Equipment: RUGGEDCOM ROX IIB
- Vulnerabilities: Improper Input Validation, NULL Pointer Dereference, Out-of-Bounds Write, Insufficient Verification of Data Authenticity, Improper Certificate Validation, Out-of-bounds Read
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow the decryption of encrypted content, possible code execution, or cause a sy
Ubuntu
NSS vulnerability
vendor_ubuntu·2019-12-09
CVE-2019-17007 NSS vulnerability
Title: NSS vulnerability
Summary: NSS could be made to crash if it received a specially crafted certificate.
It was discovered that NSS incorrectly handled certain certificates.
An attacker could possibly use this issue to cause a denial of service.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
nss: Handling of Netscape Certificate Sequences in CERT_DecodeCertPackage() may crash with a NULL deref leading to DoS
vendor_redhat·2019-03-21·CVSS 7.5
CVE-2019-17007 [HIGH] CWE-476 nss: Handling of Netscape Certificate Sequences in CERT_DecodeCertPackage() may crash with a NULL deref leading to DoS
nss: Handling of Netscape Certificate Sequences in CERT_DecodeCertPackage() may crash with a NULL deref leading to DoS
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
Statement: This issue was addressed via upstream nss-3.44, which is already shipped with Red Hat Enterprise Linux 6, 7 and 8.
Package: nss (Red Hat JBoss Enterprise Application Platform 6) - Out of support scope
Debian
CVE-2019-17007: nss - In Network Security Services before 3.44, a malformed Netscape Certificate Seque...
vendor_debian·2019·CVSS 7.5
CVE-2019-17007 [HIGH] CVE-2019-17007: nss - In Network Security Services before 3.44, a malformed Netscape Certificate Seque...
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
Scope: local
bookworm: resolved (fixed in 2:3.45-1)
bullseye: resolved (fixed in 2:3.45-1)
forky: resolved (fixed in 2:3.45-1)
sid: resolved (fixed in 2:3.45-1)
trixie: resolved (fixed in 2:3.45-1)
GHSA
GHSA-fcjm-r5rj-fq7w: In Network Security Services before 3
ghsa_unreviewed·2022-05-24
CVE-2019-17007 [HIGH] CWE-295 GHSA-fcjm-r5rj-fq7w: In Network Security Services before 3
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
OSV
CVE-2019-17007: In Network Security Services before 3
osv·2020-10-22·CVSS 7.5
CVE-2019-17007 [HIGH] CVE-2019-17007: In Network Security Services before 3
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
No detection rules found.
No public exploits indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=1533216https://cert-portal.siemens.com/productcert/pdf/ssa-379803.pdfhttps://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.44_release_noteshttps://us-cert.cisa.gov/ics/advisories/icsa-21-040-04https://bugzilla.mozilla.org/show_bug.cgi?id=1533216https://cert-portal.siemens.com/productcert/pdf/ssa-379803.pdfhttps://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.44_release_noteshttps://us-cert.cisa.gov/ics/advisories/icsa-21-040-04
2020-10-22
Published