CVE-2019-17007

Description

In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.308

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2.4Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 12.0.3Windows
Network Security Service library (USN-4215-1) libnss3_3.35-2ubuntu2.6_i386.debLinux
Network Security Service library (USN-4215-1) libnss3_3.35-2ubuntu2.6_amd64.debLinux
Network Security Service library (USN-4215-1) libnss3_3.42-1ubuntu2.4_i386.debLinux
Network Security Service library (USN-4215-1) libnss3_3.42-1ubuntu2.4_amd64.debLinux
Network Security Service library (USN-4215-1) libnss3_3.28.4-0ubuntu0.16.04.9_i386.debLinux
Network Security Service library (USN-4215-1) libnss3_3.28.4-0ubuntu0.16.04.9_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234