nss: Empty or malformed p256-ECDH public keys may trigger a segmentation fault
Published Jul 23, 2019
7.5
HIGHCVSS 3.1
EPSS 2.79%
Description
Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memory and used. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<68
- Version
-
- Version unspecifiedStatusaffectedConstraints<60.8
- Version
-
- Version unspecifiedStatusaffectedConstraints<60.8
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mozilla | Firefox | n/a |
| ||||||
| Mozilla | Firefox ESR | n/a |
| ||||||
| Mozilla | Thunderbird | n/a |
|
No data.
Red Hat Ansible Tower 3.4 for RHEL 7
ansible-tower-34/ansible-tower-memcached:1.4.15-28
Fixed · RHBA-2020:0547
Red Hat Ansible Tower 3.4 for RHEL 7
ansible-tower-35/ansible-tower-memcached:1.4.15-28
Fixed · RHBA-2020:0547
Red Hat Ansible Tower 3.4 for RHEL 7
ansible-tower-37/ansible-tower-memcached-rhel7:1.4.15-28
Fixed · RHBA-2020:0547
Red Hat Enterprise Linux 7
nss-0:3.44.0-7.el7_7
Fixed · RHSA-2019:4190
Red Hat Enterprise Linux 7
nss-softokn-0:3.44.0-8.el7_7
Fixed · RHSA-2019:4190
Red Hat Enterprise Linux 7
nss-util-0:3.44.0-4.el7_7
Fixed · RHSA-2019:4190
Red Hat Enterprise Linux 8
nspr-0:4.21.0-2.el8_0
Fixed · RHSA-2019:1951
Red Hat Enterprise Linux 8
nss-0:3.44.0-7.el8_0
Fixed · RHSA-2019:1951
Red Hat Enterprise Linux 5
firefox
Out of support scope
Red Hat Enterprise Linux 6
firefox
Not affected
Red Hat Enterprise Linux 6
nss
Out of support scope
Red Hat Enterprise Linux 7
firefox
Not affected
Red Hat Enterprise Linux 8
firefox
Not affected
Red Hat JBoss Enterprise Application Platform 6
nss
Out of support scope
Red Hat OpenShift Container Platform 4
nss-altfiles
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Tower 3.4 for RHEL 7 | ansible-tower-34/ansible-tower-memcached:1.4.15-28 | Fixed | RHBA-2020:0547 |
| Red Hat Ansible Tower 3.4 for RHEL 7 | ansible-tower-35/ansible-tower-memcached:1.4.15-28 | Fixed | RHBA-2020:0547 |
| Red Hat Ansible Tower 3.4 for RHEL 7 | ansible-tower-37/ansible-tower-memcached-rhel7:1.4.15-28 | Fixed | RHBA-2020:0547 |
| Red Hat Enterprise Linux 7 | nss-0:3.44.0-7.el7_7 | Fixed | RHSA-2019:4190 |
| Red Hat Enterprise Linux 7 | nss-softokn-0:3.44.0-8.el7_7 | Fixed | RHSA-2019:4190 |
| Red Hat Enterprise Linux 7 | nss-util-0:3.44.0-4.el7_7 | Fixed | RHSA-2019:4190 |
| Red Hat Enterprise Linux 8 | nspr-0:4.21.0-2.el8_0 | Fixed | RHSA-2019:1951 |
| Red Hat Enterprise Linux 8 | nss-0:3.44.0-7.el8_0 | Fixed | RHSA-2019:1951 |
| Red Hat Enterprise Linux 5 | firefox | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 6 | nss | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | firefox | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | nss | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | nss-altfiles | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Firefox on Red Hat Enterprise Linux is built against the system nss library.
References (19)
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00055.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00058.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00073.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00009.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00010.html vendor-advisoryx_refsource_SUSE
- https://access.redhat.com/errata/RHSA-2019:1951 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:4190 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2019-11729 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1515342 x_refsource_MISCIssue TrackingPermissions RequiredVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1728437 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2020/09/msg00029.html mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2019-11729
- https://security.gentoo.org/glsa/201908-12 vendor-advisoryx_refsource_GENTOO
- https://security.gentoo.org/glsa/201908-20 vendor-advisoryx_refsource_GENTOO
- https://www.cve.org/CVERecord?id=CVE-2019-11729
- https://www.mozilla.org/en-US/security/advisories/mfsa2019-22/#CVE-2019-11729
- https://www.mozilla.org/security/advisories/mfsa2019-21/ x_refsource_MISCVendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-22/ x_refsource_MISCVendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2019-23/ x_refsource_MISCVendor Advisory
Change history (0)
No recorded changes yet.