CVE-2022-3479: High severity ibm cognos analytics vulnerability
A vulnerability found in nss. By this security vulnerability, nss client auth crash without a user certificate in the database and this can lead us to a segmentation fault or crash.
Other sources
Mozilla Network Security Services (NSS), as used in Mozilla Firefox, is vulnerable to a denial of service, caused by a segmentation fault when there is not a user certificate in the database. A remote attacker could exploit this vulnerability to cause the nss client auth to crash.
— IBM
nss client auth crash without a user certificate in the database
BZ ID: https://bugzilla.redhat.com/showbug.cgi?id=2129433 Upstream: https://bugzilla.mozilla.org/showbug.cgi?id=1774654
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-3479?
CVE-2022-3479 is a vulnerability found in nss where the client auth can crash without a user certificate, leading to a segmentation fault or crash.
What is the severity of CVE-2022-3479?
CVE-2022-3479 has a severity level of medium.
Which software is affected by CVE-2022-3479?
The software affected by CVE-2022-3479 includes nss versions 2:3.82-1ubuntu0.1, 3.81 (Red Hat), and various versions (2:3.42.1-1+deb10u5, 2:3.42.1-1+deb10u6, 2:3.61-1+deb11u3, 2:3.87.1-1, 2:3.92-1) on Debian.
How can I fix CVE-2022-3479 on Ubuntu?
To fix CVE-2022-3479 on Ubuntu, update the nss package to version 2:3.82-1ubuntu0.1 or later.
Where can I find more information about CVE-2022-3479?
You can find more information about CVE-2022-3479 at the following references: [1](https://bugzilla.mozilla.org/show_bug.cgi?id=1774654), [2](https://bugzilla.redhat.com/show_bug.cgi?id=2134331), [3](https://security.gentoo.org/glsa/202212-05).