Description
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS < 3.73 and NSS < 3.68.1.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2836-1 | nss security update |
Debian DLA |
DLA-2836-2 | nss regression update |
Debian DSA |
DSA-5016-1 | nss security update |
EUVD |
EUVD-2021-30456 | NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS < 3.73 and NSS < 3.68.1. |
Ubuntu USN |
USN-5168-1 | NSS vulnerability |
Ubuntu USN |
USN-5168-2 | Thunderbird vulnerability |
Ubuntu USN |
USN-5168-3 | NSS vulnerability |
Ubuntu USN |
USN-5168-4 | NSS regression |
References
History
No history.
Subscriptions
Mozilla
Subscribe
Nss
Subscribe
Nss Esr
Subscribe
Netapp
Subscribe
Cloud Backup
Subscribe
E-series Santricity Os Controller
Subscribe
Oracle
Subscribe
Communications Cloud Native Core Binding Support Function
Subscribe
Communications Cloud Native Core Network Repository Function
Subscribe
Communications Cloud Native Core Network Slice Selection Function
Subscribe
Communications Policy Management
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Rhel Aus
Subscribe
Rhel E4s
Subscribe
Rhel Els
Subscribe
Rhel Eus
Subscribe
Rhel Tus
Subscribe
Rhev Hypervisor
Subscribe
Starwindsoftware
Subscribe
Starwind San \& Nas
Subscribe
Starwind Virtual San
Subscribe
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-08-04T03:55:29.297Z
Reserved: 2021-11-08T00:00:00.000Z
Link: CVE-2021-43527
No data.
Status : Modified
Published: 2021-12-08T22:15:09.163
Modified: 2024-11-21T06:29:21.467
Link: CVE-2021-43527
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN