[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249966

 
 

909

 
 

195636

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2020-1559 --- nspr, nss, nss-util, nss-softokn

ID: oval:org.secpod.oval:def:1700469Date: (C)2020-11-24   (M)2024-04-17
Class: PATCHFamily: unix




When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services library. This could lead to information disclosure. This vulnerability affects Firefox ESR CVE-2019-11719 (NSS

Platform:
Amazon Linux 2
Product:
nspr
nss-softokn
nss
nss-util
Reference:
ALAS2-2020-1559
CVE-2019-11719
CVE-2019-11727
CVE-2019-11756
CVE-2019-17006
CVE-2019-17023
CVE-2020-12400
CVE-2020-12401
CVE-2020-12402
CVE-2020-12403
CVE-2020-6829
CVE    10
CVE-2020-12402
CVE-2020-12401
CVE-2020-12400
CVE-2020-12403
...

© SecPod Technologies