First published: Fri Jul 14 2017(Updated: )
Potential use-after-free vulnerability in nss in TLS 1.2 server when verifying client authentication was found. Upstream bug: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1377618">https://bugzilla.mozilla.org/show_bug.cgi?id=1377618</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Network Security Services (NSS) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-1471171 is classified as a potential use-after-free vulnerability which can impact the security of TLS 1.2 server client authentication.
To fix REDHAT-BUG-1471171, update your Mozilla NSS to the latest version that includes the security patch.
The affected software for REDHAT-BUG-1471171 is Mozilla Network Security Services (NSS).
The vulnerability in REDHAT-BUG-1471171 can lead to unauthorized access during the client authentication process.
Currently, there is no documented workaround for REDHAT-BUG-1471171; the recommended action is to apply the security update.