Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote attacker.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2017:1365 | vendor advisory |
http://www.securitytracker.com/id/1038579 | vdb entry |
http://www.securityfocus.com/bid/98744 | third party advisory vdb entry |
https://access.redhat.com/errata/RHSA-2017:1712 | vendor advisory |
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html | |
https://hg.mozilla.org/projects/nss/rev/55ea60effd0d | patch |
https://access.redhat.com/errata/RHSA-2017:1364 | vendor advisory |
https://access.redhat.com/errata/RHSA-2017:1567 | vendor advisory |
http://www.debian.org/security/2017/dsa-3872 | vendor advisory |