In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.44_release_notes | release notes vendor advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=1533216 | issue tracking patch vendor advisory exploit |
https://cert-portal.siemens.com/productcert/pdf/ssa-379803.pdf | third party advisory |
https://us-cert.cisa.gov/ics/advisories/icsa-21-040-04 | third party advisory us government resource |