A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Nss | Mozilla | * | 3.26 (excluding) |
Red Hat Enterprise Linux 5 | RedHat | nss-0:3.21.3-2.el5_11 | * |
Red Hat Enterprise Linux 6 | RedHat | nss-0:3.21.3-2.el6_8 | * |
Red Hat Enterprise Linux 6 | RedHat | nss-util-0:3.21.3-1.el6_8 | * |
Red Hat Enterprise Linux 7 | RedHat | nss-0:3.21.3-2.el7_3 | * |
Red Hat Enterprise Linux 7 | RedHat | nss-util-0:3.21.3-1.1.el7_3 | * |
Nss | Ubuntu | precise | * |
Nss | Ubuntu | trusty | * |
Nss | Ubuntu | upstream | * |
Nss | Ubuntu | vivid/stable-phone-overlay | * |
Nss | Ubuntu | xenial | * |