CVE-2018-18508: Null Pointer Dereference
A NULL pointer dereference issue was found in several CMS function. A specially crafted data could possibly crash nss.
External References:
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS3.41.1releasenotes
Other sources
In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service.
Mozilla Network Security Services (NSS), as used in Mozilla Firefox, is vulnerable to a denial of service, caused by a NULL pointer dereference in several CMS functions. By sending specially crafted data, a remote attacker could exploit this vulnerability to cause the server to crash.
— IBM
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2018-18508.
What is the severity of CVE-2018-18508?
The severity of CVE-2018-18508 is medium with a CVSS score of 6.5.
Which software versions are affected by CVE-2018-18508?
Versions before 3.36.7 and before 3.41.1 of Network Security Services (NSS) are affected by CVE-2018-18508.
How can a malformed signature cause a crash due to a null dereference?
A malformed signature can cause a crash due to a null dereference by exploiting a vulnerability in the Network Security Services (NSS) library.
How can I fix CVE-2018-18508?
To fix CVE-2018-18508, update to version 3.41.1 or later of Network Security Services (NSS).