CVE-2019-17006
22.10.2020, 21:15
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.Enginsight
| Vendor | Product | Version |
|---|---|---|
| siemens | ruggedcom_rox_mx5000_firmware | 𝑥 < 2.14.0 |
| siemens | ruggedcom_rox_rx1400_firmware | 𝑥 < 2.14.0 |
| siemens | ruggedcom_rox_rx1500_firmware | 𝑥 < 2.14.0 |
| siemens | ruggedcom_rox_rx1501_firmware | 𝑥 < 2.14.0 |
| siemens | ruggedcom_rox_rx1510_firmware | 𝑥 < 2.14.0 |
| siemens | ruggedcom_rox_rx1511_firmware | 𝑥 < 2.14.0 |
| siemens | ruggedcom_rox_rx1512_firmware | 𝑥 < 2.14.0 |
| siemens | ruggedcom_rox_rx5000_firmware | 𝑥 < 2.14.0 |
| mozilla | network_security_services | 𝑥 < 3.46 |
| netapp | hci_management_node | - |
| netapp | solidfire | - |
| netapp | hci_compute_node | - |
| netapp | hci_storage_node | - |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References