CVE-2018-18508

Description

In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.558

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2.4Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 12.0.3Windows
Network Security Service library (USN-3898-1) libnss3_3.35-2ubuntu2.2_i386.debLinux
Network Security Service library (USN-3898-1) libnss3_3.35-2ubuntu2.2_amd64.debLinux
Network Security Service library (USN-3898-1) libnss3_3.36.1-1ubuntu1.2_i386.debLinux
Network Security Service library (USN-3898-1) libnss3_3.36.1-1ubuntu1.2_amd64.debLinux
Network Security Service library (USN-3898-1) libnss3_3.28.4-0ubuntu0.14.04.5_i386.debLinux
Network Security Service library (USN-3898-1) libnss3_3.28.4-0ubuntu0.14.04.5_amd64.debLinux
Network Security Service library (USN-3898-1) libnss3_3.28.4-0ubuntu0.16.04.5_i386.debLinux
Network Security Service library (USN-3898-1) libnss3_3.28.4-0ubuntu0.16.04.5_amd64.debLinux
(RHSA-2019:1951) nss and nspr security, bug fix, and enhancement update nspr-4.21.0-2.el8_0.i686.rpmLinux
(RHSA-2019:1951) nss and nspr security, bug fix, and enhancement update nspr-4.21.0-2.el8_0.x86_64.rpmLinux
(RHSA-2019:1951) nss and nspr security, bug fix, and enhancement update nspr-debugsource-4.21.0-2.el8_0.i686.rpmLinux
(RHSA-2019:1951) nss and nspr security, bug fix, and enhancement update nspr-debugsource-4.21.0-2.el8_0.x86_64.rpmLinux
(RHSA-2019:1951) nss and nspr security, bug fix, and enhancement update nspr-devel-4.21.0-2.el8_0.i686.rpmLinux
(RHSA-2019:1951) nss and nspr security, bug fix, and enhancement update nspr-devel-4.21.0-2.el8_0.x86_64.rpmLinux
(CESA-2019:1951) nss and nspr security, bug fix, and enhancement update nspr-4.21.0-2.el8_0.i686.rpmLinux
(CESA-2019:1951) nss and nspr security, bug fix, and enhancement update nspr-4.21.0-2.el8_0.x86_64.rpmLinux
(CESA-2019:1951) nss and nspr security, bug fix, and enhancement update nspr-devel-4.21.0-2.el8_0.i686.rpmLinux
(CESA-2019:1951) nss and nspr security, bug fix, and enhancement update nspr-devel-4.21.0-2.el8_0.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234