PT-2018-2701 · Mozilla+5 · Network Security Services+5
Published
2018-07-05
·
Updated
2021-02-18
·
CVE-2018-18508
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Network Security Services (NSS) versions prior to 3.36.7
Network Security Services (NSS) versions prior to 3.41.1
Description
A malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service. The vulnerability is related to errors in pointer dereferencing in the Certificate Management Server (CMS) component of the NSS library. Exploitation of the vulnerability may allow a remote attacker to cause a denial of service.
Recommendations
For versions prior to 3.36.7, update to version 3.36.7 or later.
For versions prior to 3.41.1, update to version 3.41.1 or later.
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Network Security Services
Red Hat
Suse
Ubuntu