In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Network_security_services | Mozilla | * | 3.36.7 (excluding) |
Network_security_services | Mozilla | 3.41 (including) | 3.41.1 (excluding) |
Red Hat Enterprise Linux 8 | RedHat | nspr-0:4.21.0-2.el8_0 | * |
Red Hat Enterprise Linux 8 | RedHat | nss-0:3.44.0-7.el8_0 | * |
Nss | Ubuntu | bionic | * |
Nss | Ubuntu | cosmic | * |
Nss | Ubuntu | devel | * |
Nss | Ubuntu | trusty | * |
Nss | Ubuntu | upstream | * |
Nss | Ubuntu | xenial | * |