PT-2021-5576 · Mozilla+11 · Thunderbird+13

Yaoguang Chen

·

Published

2021-12-01

·

Updated

2025-07-16

·

CVE-2021-43527

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions NSS versions prior to 3.73 or 3.68.1 ESR
Description The issue is related to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS #7, or PKCS #12 are likely to be impacted. Email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution, and Evince, are believed to be impacted. The vulnerability may allow a remote attacker to execute arbitrary code.
Recommendations For NSS versions prior to 3.73 or 3.68.1 ESR, update to version 3.73 or 3.68.1 ESR or later to resolve the issue. As a temporary workaround, consider disabling the use of DER-encoded DSA or RSA-PSS signatures until a patch is available. Restrict access to vulnerable applications, such as email clients and PDF viewers, to minimize the risk of exploitation.

Fix

Heap Based Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4903
ALT-PU-2021-3441
ALT-PU-2022-2928
ALT-PU-2023-1136
ALT-PU-2023-4338
AZL-7024
BDU:2022-00002
CESA-2021_4903
CESA-2021_4904
CVE-2021-43527
DLA-2836-1
DLA-2836-2
DSA-5016-1
MGASA-2021-0534
OESA-2022-1492
OPENSUSE-SU-2021:3934-1
OPENSUSE-SU-2021_3934-1
OPENSUSE-SU-2024:11663-1
RHSA-2021:4130
RHSA-2021:4132
RHSA-2021:4133
RHSA-2021:4134
RHSA-2021:4903
RHSA-2021:4904
RHSA-2021:4907
RHSA-2021:4909
RHSA-2021:4919
RHSA-2021:4932
RHSA-2021:4933
RHSA-2021:4946
RHSA-2021:4953
RHSA-2021:4954
RHSA-2021:4969
RHSA-2021:4994
RHSA-2021:5006
RHSA-2021:5035
RHSA-2021_4903
RHSA-2021_4904
RHSA-2021_4907
RLSA-2021:4903
SUSE-SU-2021:14858-1
SUSE-SU-2021:3934-1
SUSE-SU-2021:3939-1
SUSE-SU-2021_14858-1
SUSE-SU-2021_3934-1
SUSE-SU-2021_3939-1
SUSE-SU-2022:2536-1
SUSE-SU-2022_2536-1
SUSE-SU-2024:2008-1
SUSE-SU-2024:2010-1
SUSE-SU-2024:2011-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2183-1
SUSE-SU-2024:2185-1
SUSE-SU-2024:2189-1
SUSE-SU-2024:2190-1
SUSE-SU-2025:02334-1
USN-5168-1
USN-5168-2
USN-5168-3
USN-5168-4

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Evince
Evolution
Libreoffice
Linuxmint
Nss
Red Hat
Rocky Linux
Suse
Thunderbird
Ubuntu