CVE-2019-17006
CVE-2019-17006
Vexday Risk Score
3Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS —EPSS 3.6%KEV nãoPoC —Patch —
Ciclo de vida
22 out 2020Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.
Produtos afetados
Mozilla · NSSQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://bugzilla.mozilla.org/show_bug.cgi?id=1539788https://cert-portal.siemens.com/productcert/pdf/ssa-379803.pdfhttps://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.46_release_noteshttps://security.netapp.com/advisory/ntap-20210129-0001/https://us-cert.cisa.gov/ics/advisories/icsa-21-040-04