PT-2021-5576 · Mozilla+11 · Thunderbird+13
Yaoguang Chen
·
Published
2021-12-01
·
Updated
2025-07-16
·
CVE-2021-43527
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NSS versions prior to 3.73 or 3.68.1 ESR
Description
The issue is related to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS #7, or PKCS #12 are likely to be impacted. Email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution, and Evince, are believed to be impacted. The vulnerability may allow a remote attacker to execute arbitrary code.
Recommendations
For NSS versions prior to 3.73 or 3.68.1 ESR, update to version 3.73 or 3.68.1 ESR or later to resolve the issue. As a temporary workaround, consider disabling the use of DER-encoded DSA or RSA-PSS signatures until a patch is available. Restrict access to vulnerable applications, such as email clients and PDF viewers, to minimize the risk of exploitation.
Fix
Heap Based Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Evince
Evolution
Libreoffice
Linuxmint
Nss
Red Hat
Rocky Linux
Suse
Thunderbird
Ubuntu