CVE-2019-17007

In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
mozillaCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 50%
Affected Products (NVD)
VendorProductVersion
mozillanetwork_security_services
𝑥
< 3.44
siemensruggedcom_rox_mx5000_firmware
𝑥
< 2.14.0
siemensruggedcom_rox_rx1400_firmware
𝑥
< 2.14.0
siemensruggedcom_rox_rx1500_firmware
𝑥
< 2.14.0
siemensruggedcom_rox_rx1501_firmware
𝑥
< 2.14.0
siemensruggedcom_rox_rx1510_firmware
𝑥
< 2.14.0
siemensruggedcom_rox_rx1511_firmware
𝑥
< 2.14.0
siemensruggedcom_rox_rx1512_firmware
𝑥
< 2.14.0
siemensruggedcom_rox_rx5000_firmware
𝑥
< 2.14.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
mozillanss
𝑥
< 3.44
CNA
Debian logo
Debian Releases
Debian Product
Codename
nss
bookworm
2:3.87.1-1
fixed
bullseye
2:3.61-1+deb11u3
fixed
bullseye (security)
2:3.61-1+deb11u4
fixed
sid
2:3.105-2
fixed
trixie
2:3.105-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
nss
bionic
Fixed 2:3.35-2ubuntu2.6
released
disco
Fixed 2:3.42-1ubuntu2.4
released
eoan
not-affected
trusty
Fixed 2:3.28.4-0ubuntu0.14.04.5+esm3
released
xenial
Fixed 2:3.28.4-0ubuntu0.16.04.9
released
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
nspr
RHEL 6
0:4.21.0-1.el6_10
fixed
RHEL 7
0:4.21.0-1.el7
fixed
RHEL 8
0:4.21.0-2.el8_0
fixed
RHEL 8.0 E4S
0:4.21.0-2.el8_0
fixed
nspr-devel
RHEL 6
0:4.21.0-1.el6_10
fixed
RHEL 7
0:4.21.0-1.el7
fixed
RHEL 8
0:4.21.0-2.el8_0
fixed
RHEL 8.0 E4S
0:4.21.0-2.el8_0
fixed
nss
RHEL 6
0:3.44.0-7.el6_10
fixed
RHEL 7
0:3.44.0-4.el7
fixed
RHEL 8
0:3.44.0-7.el8_0
fixed
RHEL 8.0 E4S
0:3.44.0-7.el8_0
fixed
nss-devel
RHEL 6
0:3.44.0-7.el6_10
fixed
RHEL 7
0:3.44.0-4.el7
fixed
RHEL 8
0:3.44.0-7.el8_0
fixed
RHEL 8.0 E4S
0:3.44.0-7.el8_0
fixed
nss-pkcs11-devel
RHEL 6
0:3.44.0-7.el6_10
fixed
RHEL 7
0:3.44.0-4.el7
fixed
nss-softokn
RHEL 6
0:3.44.0-5.el6_10
fixed
RHEL 7
0:3.44.0-5.el7
fixed
RHEL 8
0:3.44.0-7.el8_0
fixed
RHEL 8.0 E4S
0:3.44.0-7.el8_0
fixed
nss-softokn-devel
RHEL 6
0:3.44.0-5.el6_10
fixed
RHEL 7
0:3.44.0-5.el7
fixed
RHEL 8
0:3.44.0-7.el8_0
fixed
RHEL 8.0 E4S
0:3.44.0-7.el8_0
fixed
nss-softokn-freebl
RHEL 6
0:3.44.0-5.el6_10
fixed
RHEL 7
0:3.44.0-5.el7
fixed
RHEL 8
0:3.44.0-7.el8_0
fixed
RHEL 8.0 E4S
0:3.44.0-7.el8_0
fixed
nss-softokn-freebl-devel
RHEL 6
0:3.44.0-5.el6_10
fixed
RHEL 7
0:3.44.0-5.el7
fixed
RHEL 8
0:3.44.0-7.el8_0
fixed
RHEL 8.0 E4S
0:3.44.0-7.el8_0
fixed
nss-sysinit
RHEL 6
0:3.44.0-7.el6_10
fixed
RHEL 7
0:3.44.0-4.el7
fixed
RHEL 8
0:3.44.0-7.el8_0
fixed
RHEL 8.0 E4S
0:3.44.0-7.el8_0
fixed
nss-tools
RHEL 6
0:3.44.0-7.el6_10
fixed
RHEL 7
0:3.44.0-4.el7
fixed
RHEL 8
0:3.44.0-7.el8_0
fixed
RHEL 8.0 E4S
0:3.44.0-7.el8_0
fixed
nss-util
RHEL 6
0:3.44.0-1.el6_10
fixed
RHEL 7
0:3.44.0-3.el7
fixed
RHEL 8
0:3.44.0-7.el8_0
fixed
RHEL 8.0 E4S
0:3.44.0-7.el8_0
fixed
nss-util-devel
RHEL 6
0:3.44.0-1.el6_10
fixed
RHEL 7
0:3.44.0-3.el7
fixed
RHEL 8
0:3.44.0-7.el8_0
fixed
RHEL 8.0 E4S
0:3.44.0-7.el8_0
fixed