vulnerability
Amazon Linux 2023: CVE-2021-43527: Critical priority package update for nss
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
10 | (AV:N/AC:L/Au:N/C:C/I:C/A:C) | 2021-12-01 | 2025-02-17 | 2025-02-17 |
Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
2021-12-01
Added
2025-02-17
Modified
2025-02-17
Description
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS < 3.73 and NSS < 3.68.1.
A remote code execution flaw was found in the way NSS verifies certificates. This flaw allows an attacker posing as an SSL/TLS server to trigger this issue in a client application compiled with NSS when it tries to initiate an SSL/TLS connection. Similarly, a server application compiled with NSS, which processes client certificates, can receive a malicious certificate via a client, triggering the flaw. The highest threat to this vulnerability is confidentiality, integrity, as well as system availability.
A remote code execution flaw was found in the way NSS verifies certificates. This flaw allows an attacker posing as an SSL/TLS server to trigger this issue in a client application compiled with NSS when it tries to initiate an SSL/TLS connection. Similarly, a server application compiled with NSS, which processes client certificates, can receive a malicious certificate via a client, triggering the flaw. The highest threat to this vulnerability is confidentiality, integrity, as well as system availability.
Solution(s)
amazon-linux-2023-upgrade-nspramazon-linux-2023-upgrade-nspr-debuginfoamazon-linux-2023-upgrade-nspr-develamazon-linux-2023-upgrade-nssamazon-linux-2023-upgrade-nss-debuginfoamazon-linux-2023-upgrade-nss-debugsourceamazon-linux-2023-upgrade-nss-develamazon-linux-2023-upgrade-nss-pkcs11-develamazon-linux-2023-upgrade-nss-softoknamazon-linux-2023-upgrade-nss-softokn-debuginfoamazon-linux-2023-upgrade-nss-softokn-develamazon-linux-2023-upgrade-nss-softokn-freeblamazon-linux-2023-upgrade-nss-softokn-freebl-debuginfoamazon-linux-2023-upgrade-nss-softokn-freebl-develamazon-linux-2023-upgrade-nss-sysinitamazon-linux-2023-upgrade-nss-sysinit-debuginfoamazon-linux-2023-upgrade-nss-toolsamazon-linux-2023-upgrade-nss-tools-debuginfoamazon-linux-2023-upgrade-nss-utilamazon-linux-2023-upgrade-nss-util-debuginfoamazon-linux-2023-upgrade-nss-util-devel

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.