Unrated severityNVD Advisory· Published Oct 22, 2020· Updated Aug 5, 2024
CVE-2019-17006
CVE-2019-17006
Description
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.
Affected products
1- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- bugzilla.mozilla.org/show_bug.cgimitrex_refsource_MISC
- cert-portal.siemens.com/productcert/pdf/ssa-379803.pdfmitrex_refsource_CONFIRM
- developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.46_release_notesmitrex_refsource_MISC
- security.netapp.com/advisory/ntap-20210129-0001/mitrex_refsource_CONFIRM
- us-cert.cisa.gov/ics/advisories/icsa-21-040-04mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.