CVE-2019-17007: Null Pointer Dereference
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
Other sources
Main entrypoint for decoding DER blobs in NSS, CERTDecodeCertPackage() mishandles old Netscape Certificate Sequences, with possible crash as NULL pointer is dereferenced, leading to DoS.
External References: https://bugs.chromium.org/p/project-zero/issues/detail?id=1798
— Red Hat
Mozilla Network Security Services (NSS), as used in Mozilla Firefox is vulnerable to a denial of service, caused by a NULL pointer dereference when handling Netscape Certificate Sequences in CERTDecodeCertPackage(). A remote attacker could exploit this vulnerability to cause the library to crash.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-17007?
CVE-2019-17007 is a vulnerability in Network Security Services (NSS) before version 3.44.
How does CVE-2019-17007 affect systems?
CVE-2019-17007 can cause NSS to crash, resulting in a denial of service.
What is the severity of CVE-2019-17007?
The severity of CVE-2019-17007 is high, with a CVSS score of 7.5.
How do I fix CVE-2019-17007?
To fix CVE-2019-17007, update Network Security Services (NSS) to version 3.44 or later.
Where can I find more information about CVE-2019-17007?
You can find more information about CVE-2019-17007 on the following references: 1. [Chromium Project Zero](https://bugs.chromium.org/p/project-zero/issues/detail?id=1798) 2. [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1703987) 3. [Mozilla NSS Repository](https://hg.mozilla.org/projects/nss/rev/1473dd7efe2ce4f8722a33ebb03a3425e09887de)