CVE-2021-43527
published 2021-12-08CVE-2021-43527: NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures…
PriorityP265critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
17.56%
96.8th percentile
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS < 3.73 and NSS < 3.68.1.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nss | < nss 2:3.73-1 (bookworm) | nss 2:3.73-1 (bookworm) |
| debian | thunderbird | < thunderbird 1:91.3.0-1 (bookworm) | thunderbird 1:91.3.0-1 (bookworm) |
| chrome_chrome | — | — | |
| mozilla | firefox | — | — |
| mozilla | nss | < 3.73 | 3.73 |
| mozilla | nss | >= 0 < 2:3.61-1+deb11u1 | 2:3.61-1+deb11u1 |
| mozilla | nss | >= 0 < 2:3.73-1 | 2:3.73-1 |
| mozilla | nss | >= 0 < 2:3.73-1 | 2:3.73-1 |
| mozilla | nss | >= 0 < 2:3.73-1 | 2:3.73-1 |
| mozilla | nss_esr | < 3.68.1 | 3.68.1 |
| mozilla | thunderbird | < 91.3.0 | 91.3.0 |
| mozilla | thunderbird | >= 0 < 1:91.4.1-1~deb11u1 | 1:91.4.1-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:91.3.0-1 | 1:91.3.0-1 |
| mozilla | thunderbird | >= 0 < 1:91.3.0-1 | 1:91.3.0-1 |
| mozilla | thunderbird | >= 0 < 1:91.3.0-1 | 1:91.3.0-1 |
| mozilla | thunderbird | >= unspecified < 91.3.0 | 91.3.0 |
| msrc | cbl2_nss_3.75-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_nss_3.73-1_on_cbl_mariner_1.0 | — | — |
| netapp | e-series_santricity_os_controller | 11.0 – 11.70.1 | — |
| oracle | communications_cloud_native_core_binding_support_function | — | — |
| oracle | communications_cloud_native_core_network_repository_function | — | — |
| oracle | communications_cloud_native_core_network_repository_function | — | — |
| oracle | communications_cloud_native_core_network_slice_selection_function | — | — |
| oracle | communications_policy_management | — | — |
| paloalto | pan-os | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Heap overflow is triggered during DER-encoded DSA or RSA-PSS signature verification in NSS; monitor for crashes or memory corruption in NSS-linked processes (e.g., Thunderbird, LibreOffice, Evolution, Evince) during certificate/signature validation ↗
- →Attack vector includes TLS handshake: an attacker posing as an SSL/TLS server can trigger the flaw in a client application compiled with NSS; also triggerable via a malicious client certificate sent to an NSS-compiled server ↗
- →S/MIME email parsing is an attack surface: Thunderbird is affected when parsing email with an S/MIME signature; flag anomalous S/MIME-signed emails delivered to NSS-linked mail clients ↗
- →Vulnerable code path is in the decodeECorDsaSignature function within NSS; look for crash dumps or stack traces referencing this function in NSS-linked applications ↗
- →Firefox is NOT vulnerable (uses mozilla::pkix for certificate verification); do not conflate Firefox crashes with this CVE — focus detection on Thunderbird, LibreOffice, Evolution, and Evince ↗
- ·Thunderbird on RHEL 8.4 and later uses the system NSS library and does not need a separate Thunderbird update; earlier RHEL 8 extended life streams require updating both Thunderbird and NSS ↗
- ·TLS certificate validation, X.509, OCSP, and CRL functionality in NSS-linked applications may also be impacted depending on NSS configuration — scope of exposure is broader than just S/MIME ↗
- ·Thunderbird fixed in version 91.3 per Mozilla advisory; ensure Thunderbird deployments are at or above this version ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
vendor_paloalto·2024-04-10·CVSS 9.8
CVE-2015-5739 [CRITICAL] PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2015-5739 This CVE is fixed in PAN-OS 11.0.4, and all later PAN-OS versions. CVE-2016-10228 This CVE is fixed in PAN-OS 11.1.3, and all later PAN-OS versions. CVE-2017-8923 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2017-9120 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2018-25009 This CVE is fixed in PAN-OS 10.2.8, 11.0.4, 11.1.3, and all later PAN-OS versions. CVE-2
Oracle
Oracle Oracle Systems Risk Matrix: XCP Firmware (NSS) — CVE-2021-43527
vendor_oracle·2024-01-15·CVSS 9.8
CVE-2021-43527 [CRITICAL] Oracle Oracle Systems Risk Matrix: XCP Firmware (NSS) — CVE-2021-43527
Oracle Oracle Systems Risk Matrix: XCP Firmware (NSS) vulnerability
CVE: CVE-2021-43527
CVSS: 9.8
Protocol: TLS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Security (NSS) — CVE-2021-43527
vendor_oracle·2022-10-15·CVSS 9.8
CVE-2021-43527 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: Security (NSS) — CVE-2021-43527
Oracle Oracle Communications Applications Risk Matrix: Security (NSS) vulnerability
CVE: CVE-2021-43527
CVSS: 9.8
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2022-1859
vendor_chrome·2022-05-31·CVSS 9.8
CVE-2022-1859 [HIGH] Long Term Support Channel Update for ChromeOS: CVE-2022-1859
Long Term Support Channel Update for ChromeOS
CVE-2022-1859: Use after free in Performance Manager. 1297283 High CVE-2022-1636: Use after free in Performance APIs 1278608 High CVE-2021-43527 [internally reported] 1304660 High CVE-2022-23308 CrOS: Vulnerability reported in dev-libs/libxml2 1315563 Medium CVE-2022-1867: Insufficient validation of untrusted input in Data Transfer
Severity: high
Oracle
Oracle Oracle Communications Risk Matrix: BSF (NSS) — CVE-2021-43527
vendor_oracle·2022-04-15·CVSS 9.8
CVE-2021-43527 [CRITICAL] Oracle Oracle Communications Risk Matrix: BSF (NSS) — CVE-2021-43527
Oracle Oracle Communications Risk Matrix: BSF (NSS) vulnerability
CVE: CVE-2021-43527
CVSS: 9.8
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Microsoft
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatur
vendor_msrc·2021-12-14·CVSS 9.8
CVE-2021-43527 [CRITICAL] CWE-787 NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatur
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS S/MIME PKCS \#7 or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS X.509 OCSP or CRL functionality may be impacted depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However email clients and PDF viewers that use NSS for signature verification such as Thunderbird LibreOffice Evolution and Evince are believed to be impacted. This vulnerability affects NSS Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by t
Ubuntu
NSS regression
vendor_ubuntu·2021-12-07
CVE-2021-43527 NSS regression
Title: NSS regression
Summary: USN-5168-3 introduced a regression in NSS.
USN-5168-3 fixed a vulnerability in NSS. Unfortunately that update introduced
a regression that could break SSL connections. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Tavis Ormandy discovered that NSS incorrectly handled verifying DSA/RSA-PSS
signatures. A remote attacker could use this issue to cause NSS to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: After a standard system update you need to restart any applications that
use NSS, such as Evolution, to make all the necessary changes.
Red Hat
nss: Memory corruption in decodeECorDsaSignature with DSA signatures (and RSA-PSS)
vendor_redhat·2021-12-01·CVSS 9.8
CVE-2021-43527 [CRITICAL] CWE-120 nss: Memory corruption in decodeECorDsaSignature with DSA signatures (and RSA-PSS)
nss: Memory corruption in decodeECorDsaSignature with DSA signatures (and RSA-PSS)
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS < 3.73 and NSS < 3.68.1.
A r
Ubuntu
NSS vulnerability
vendor_ubuntu·2021-12-01
CVE-2021-43527 NSS vulnerability
Title: NSS vulnerability
Summary: NSS could be made to crash or run programs if it verified a specially
crafted signature.
USN-5168-1 fixed a vulnerability in NSS. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
Tavis Ormandy discovered that NSS incorrectly handled verifying DSA/RSA-PSS
signatures. A remote attacker could use this issue to cause NSS to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: After a standard system update you need to restart any applications that
use NSS, such as Evolution, to make all the necessary changes.
Ubuntu
NSS vulnerability
vendor_ubuntu·2021-12-01
CVE-2021-43527 NSS vulnerability
Title: NSS vulnerability
Summary: NSS could be made to crash or run programs if it verified a specially
crafted signature.
Tavis Ormandy discovered that NSS incorrectly handled verifying DSA/RSA-PSS
signatures. A remote attacker could use this issue to cause NSS to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: After a standard system update you need to restart any applications that
use NSS, such as Evolution, to make all the necessary changes.
Red Hat
thunderbird: Memory corruption when processing S/MIME messages
vendor_redhat·2021-12-01·CVSS 9.8
CVE-2021-43529 [CRITICAL] CWE-120 thunderbird: Memory corruption when processing S/MIME messages
thunderbird: Memory corruption when processing S/MIME messages
Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures.
A flaw was found in Thunderbird, which is vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures.
Statement: Thunderbird is affected when parsing email with the S/MIME signature. Thunderbird on Red Hat Enterprise Li
Ubuntu
Thunderbird vulnerability
vendor_ubuntu·2021-12-01
CVE-2021-43527 Thunderbird vulnerability
Title: Thunderbird vulnerability
Summary: Thunderbird could be made to crash or run programs if it verified a
specially crafted signature.
Tavis Ormandy discovered that NSS, included with Thunderbird, incorrectly
handled verifying DSA/RSA-PSS signatures. A remote attacker could use this
issue to cause Thunderbird to crash, resulting in a denial of service, or
possibly execute arbitrary code.
Instructions: After a standard system update you need to restart Thunderbird to make
all the necessary changes.
Debian
CVE-2021-43529: thunderbird - Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow describ...
vendor_debian·2021·CVSS 9.8
CVE-2021-43529 [CRITICAL] CVE-2021-43529: thunderbird - Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow describ...
Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures.
Scope: local
bookworm: resolved (fixed in 1:91.3.0-1)
bullseye: resolved (fixed in 1:91.4.1-1~deb11u1)
forky: resolved (fixed in 1:91.3.0-1)
sid: resolved (fixed in 1:91.3.0-1)
trixie: resolved (fixed in 1:91.3.0-1)
Debian
CVE-2021-43527: nss - NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnera...
vendor_debian·2021·CVSS 9.8
CVE-2021-43527 [CRITICAL] CVE-2021-43527: nss - NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnera...
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS < 3.73 and NSS < 3.68.1.
Scope: local
bookworm: resolved (fixed in 2:3.73-1)
bullseye: resolved (fixed in 2:3.61-
Mozilla
Mozilla Foundation Security Advisory 2021-50: CVE-2021-43527
vendor_mozilla·CVSS 9.8
CVE-2021-43527 [CRITICAL] Mozilla Foundation Security Advisory 2021-50: CVE-2021-43527
Mozilla Foundation Security Advisory 2021-50
CVE: CVE-2021-43527
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 91.3
Mozilla
Mozilla Foundation Security Advisory 2021-51: CVE-2021-43527
vendor_mozilla·CVSS 9.8
CVE-2021-43527 [CRITICAL] Mozilla Foundation Security Advisory 2021-51: CVE-2021-43527
Mozilla Foundation Security Advisory 2021-51
CVE: CVE-2021-43527
Product: NSS
Impact: critical
Fixed in: NSS 3.68.1
NSS 3.73
GHSA
GHSA-82q7-2fg2-4gcj: Thunderbird versions prior to 91
ghsa_unreviewed·2023-02-17·CVSS 9.8
CVE-2021-43529 [CRITICAL] CWE-787 GHSA-82q7-2fg2-4gcj: Thunderbird versions prior to 91
Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures.
OSV
CVE-2021-43529: Thunderbird versions prior to 91
osv·2023-02-16·CVSS 9.8
CVE-2021-43529 [CRITICAL] CVE-2021-43529: Thunderbird versions prior to 91
Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures.
GHSA
GHSA-7hfm-39v6-v3p5: NSS (Network Security Services) versions prior to 3
ghsa_unreviewed·2021-12-09
CVE-2021-43527 [CRITICAL] CWE-787 GHSA-7hfm-39v6-v3p5: NSS (Network Security Services) versions prior to 3
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS < 3.73 and NSS < 3.68.1.
OSV
CVE-2021-43527: NSS (Network Security Services) versions prior to 3
osv·2021-12-08·CVSS 9.8
CVE-2021-43527 [CRITICAL] CVE-2021-43527: NSS (Network Security Services) versions prior to 3
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS < 3.73 and NSS < 3.68.1.
Project0
This shouldn't have happened: A vulnerability postmortem - Project Zero
project_zero·2021-12-01
CVE-2021-43527 This shouldn't have happened: A vulnerability postmortem - Project Zero
Posted by Tavis Ormandy, Project Zero
Introduction
This is an unusual blog post. I normally write posts to highlight some hidden attack surface or interesting complex vulnerability class. This time, I want to talk about a vulnerability that is neither of those things. The striking thing about this vulnerability is just how simple it is. This should have been caught earlier, and I want to explore why that didn’t happen.
In 2021, all good bugs need a catchy name, so I’m calling this one “BigSig”.
First, let’s take a look at the bug, I’ll explain how I found it and then try to understand why we missed it for so long.
Analysis
Network Security Services (NSS) is Mozilla's widely used, cross-platform cryptography library. When you verify an ASN.1 encoded digital signature
No detection rules found.
No public exploits indexed.
Bugzilla
Automatic S/MIME cert import should use additional verification using mozilla::pkix
bugzilla·2021-10-29
Automatic S/MIME cert import should use additional verification using mozilla::pkix
Automatic S/MIME cert import should use additional verification using mozilla::pkix
When processing incoming S/MIME email that is digitally signed, we:
- (a) perform a check of the signature, including verification of the signing certificate
- (b) import the certificates that are found inside the signature, because they might be necessary for verifying the signing certificate, and also for making it possible to use these certificates in the future for encryption
The classic NSS verification is limited in its ability to perform revocation checking, in particular the current configuration used by the Gecko platform has trouble with a proxy configuration.
In addition the S/MIME implementation in NSS is hardcoded to use the classic NSS verification APIs.
Therefore in bug 324474, we had add
Bugzilla
Memory Corruption in decodeECorDsaSignature with DSA signatures (and RSA-PSS)
bugzilla·2021-10-24
Memory Corruption in decodeECorDsaSignature with DSA signatures (and RSA-PSS)
Memory Corruption in decodeECorDsaSignature with DSA signatures (and RSA-PSS)
Created attachment 9247443
decoderECorDsaSignature.pem
I've found an exploitable memory corruption flaw when validating ECDSA signatures.
The `VFYContext` structure contains a decoded digital signature from a DER encoded certificate, and is defined like this in `cryptohi/secvfy.c`:
https://searchfox.org/mozilla-central/source/security/nss/lib/cryptohi/secvfy.c#120
```
struct VFYContextStr {
SECOidTag hashAlg; /* the hash algorithm */
SECKEYPublicKey *key;
/*
* This buffer holds either the digest or the full signature
* depending on the type of the signature (key->keyType). It is
* defined as a union to make sure it always has enough space.
*
* Use the "buffer" union member to reference the buffer.
* Note: do
https://bugzilla.mozilla.org/show_bug.cgi?id=1737470https://cert-portal.siemens.com/productcert/pdf/ssa-594438.pdfhttps://ftp.mozilla.org/pub/security/nss/releases/NSS_3_68_1_RTM/https://ftp.mozilla.org/pub/security/nss/releases/NSS_3_73_RTM/https://security.gentoo.org/glsa/202212-05https://security.netapp.com/advisory/ntap-20211229-0002/https://www.mozilla.org/security/advisories/mfsa2021-51/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.starwindsoftware.com/security/sw-20220802-0001/https://bugzilla.mozilla.org/show_bug.cgi?id=1737470https://cert-portal.siemens.com/productcert/pdf/ssa-594438.pdfhttps://ftp.mozilla.org/pub/security/nss/releases/NSS_3_68_1_RTM/https://ftp.mozilla.org/pub/security/nss/releases/NSS_3_73_RTM/https://security.gentoo.org/glsa/202212-05https://security.netapp.com/advisory/ntap-20211229-0002/https://www.mozilla.org/security/advisories/mfsa2021-51/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.starwindsoftware.com/security/sw-20220802-0001/
2021-12-08
Published