CVE-2022-3479
published 2022-10-14CVE-2022-3479: A vulnerability found in nss. By this security vulnerability, nss client auth crash without a user certificate in the database and this can lead us to a…
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.70%
48.9th percentile
A vulnerability found in nss. By this security vulnerability, nss client auth crash without a user certificate in the database and this can lead us to a segmentation fault or crash.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nss | < nss 2:3.87-1 (bookworm) | nss 2:3.87-1 (bookworm) |
| mozilla | network_security_services | >= 3.77 < 3.87 | 3.87 |
| mozilla | nss | >= 0 < 2:3.87-1 | 2:3.87-1 |
| mozilla | nss | >= 0 < 2:3.87-1 | 2:3.87-1 |
| mozilla | nss | >= 0 < 2:3.87-1 | 2:3.87-1 |
| mozilla | nss | >= 0 < 2:3.35-2ubuntu2.16 | 2:3.35-2ubuntu2.16 |
| mozilla | nss | >= 0 < 2:3.49.1-1ubuntu1.9 | 2:3.49.1-1ubuntu1.9 |
| mozilla | nss | >= 0 < 2:3.68.2-0ubuntu1.2 | 2:3.68.2-0ubuntu1.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_redhat7.8HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle JD Edwards Risk Matrix: Enterprise Infrastructure SEC (NSS) — CVE-2022-3479
vendor_oracle·2024-01-15·CVSS 7.5
CVE-2022-3479 [HIGH] Oracle Oracle JD Edwards Risk Matrix: Enterprise Infrastructure SEC (NSS) — CVE-2022-3479
Oracle Oracle JD Edwards Risk Matrix: Enterprise Infrastructure SEC (NSS) vulnerability
CVE: CVE-2022-3479
CVSS: 7.5
Protocol: LDAP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Security (NSS) — CVE-2022-3479
vendor_oracle·2023-07-15·CVSS 7.5
CVE-2022-3479 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Security (NSS) — CVE-2022-3479
Oracle Oracle Communications Applications Risk Matrix: Security (NSS) vulnerability
CVE: CVE-2022-3479
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle HealthCare Applications Risk Matrix: DataStudio (NSS) — CVE-2022-3479
vendor_oracle·2023-04-15·CVSS 7.5
CVE-2022-3479 [HIGH] Oracle Oracle HealthCare Applications Risk Matrix: DataStudio (NSS) — CVE-2022-3479
Oracle Oracle HealthCare Applications Risk Matrix: DataStudio (NSS) vulnerability
CVE: CVE-2022-3479
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Ubuntu
NSS vulnerabilities
vendor_ubuntu·2023-02-27·CVSS 7.5
CVE-2022-3479 [HIGH] NSS vulnerabilities
Title: NSS vulnerabilities
Summary: Several security issues were fixed in NSS.
It was discovered that NSS incorrectly handled client authentication
without a user certificate in the database. A remote attacker could
possibly use this issue to cause a NSS client to crash, resulting in a
denial of service. This issue only affected Ubuntu 22.10. (CVE-2022-3479)
Christian Holler discovered that NSS incorrectly handled certain PKCS 12
certificated bundles. A remote attacker could use this issue to cause NSS
to crash, leading to a denial of service, or possibly execute arbitrary
code. (CVE-2023-0767)
Instructions: After a standard system update you need to restart any applications that
use NSS to make all the necessary changes.
Red Hat
nss: nss client auth crash without a user certificate in the database
vendor_redhat·2022-06-16·CVSS 7.5
CVE-2022-3479 [HIGH] nss: nss client auth crash without a user certificate in the database
nss: nss client auth crash without a user certificate in the database
A vulnerability found in nss. By this security vulnerability, nss client auth crash without a user certificate in the database and this can lead us to a segmentation fault or crash.
A vulnerability was found in NSS. The NSS client auth crashes without a user certificate in the database, leading to a segmentation fault or crash.
Package: nss (Red Hat Enterprise Linux 6) - Not affected
Package: nss (Red Hat Enterprise Linux 7) - Not affected
Package: nss (Red Hat Enterprise Linux 8) - Not affected
Package: nss (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2022-3479: nss - A vulnerability found in nss. By this security vulnerability, nss client auth cr...
vendor_debian·2022·CVSS 7.5
CVE-2022-3479 [HIGH] CVE-2022-3479: nss - A vulnerability found in nss. By this security vulnerability, nss client auth cr...
A vulnerability found in nss. By this security vulnerability, nss client auth crash without a user certificate in the database and this can lead us to a segmentation fault or crash.
Scope: local
bookworm: resolved (fixed in 2:3.87-1)
bullseye: resolved
forky: resolved (fixed in 2:3.87-1)
sid: resolved (fixed in 2:3.87-1)
trixie: resolved (fixed in 2:3.87-1)
OSV
nss vulnerabilities
osv·2023-02-27·CVSS 7.5
CVE-2022-3479 [HIGH] nss vulnerabilities
nss vulnerabilities
It was discovered that NSS incorrectly handled client authentication
without a user certificate in the database. A remote attacker could
possibly use this issue to cause a NSS client to crash, resulting in a
denial of service. This issue only affected Ubuntu 22.10. (CVE-2022-3479)
Christian Holler discovered that NSS incorrectly handled certain PKCS 12
certificated bundles. A remote attacker could use this issue to cause NSS
to crash, leading to a denial of service, or possibly execute arbitrary
code. (CVE-2023-0767)
GHSA
GHSA-6275-5f4x-m3m3: A vulnerability found in nss
ghsa_unreviewed·2022-10-14
CVE-2022-3479 [HIGH] GHSA-6275-5f4x-m3m3: A vulnerability found in nss
A vulnerability found in nss. By this security vulnerability, nss client auth crash without a user certificate in the database and this can lead us to a segmentation fault or crash.
OSV
CVE-2022-3479: A vulnerability found in nss
osv·2022-10-14·CVSS 7.5
CVE-2022-3479 [HIGH] CVE-2022-3479: A vulnerability found in nss
A vulnerability found in nss. By this security vulnerability, nss client auth crash without a user certificate in the database and this can lead us to a segmentation fault or crash.
No detection rules found.
No public exploits indexed.
2022-10-14
Published