Input validation error in Mozilla NSS - CVE-2019-11729

 

Input validation error in Mozilla NSS - CVE-2019-11729

Published: December 12, 2019


Vulnerability identifier: #VU23562
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11729
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input when processing an empty or malformed p256-ECDH public keys. A remote attacker can trigger a segmentation fault and cause a denial of service condition on the target system.


Affected software

Mozilla NSS
SUSE Package Hub for SUSE Linux Enterprise
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Slackware Linux
Opensuse
Secure Remote Services (SRS) Virtual Edition
Data Computing Appliance (DCA)
firefox-esr (Alpine package)
nss (Red Hat package)
nspr (Red Hat package)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)

How to mitigate CVE-2019-11729

Install updates from vendor's website.

Mozilla NSS - update to 3.45
Secure Remote Services (SRS) Virtual Edition - update to 3.46.00.04
firefox-esr (Alpine package) - update to 60.8.0-r0
nss (Red Hat package) - update to 3.44.0-7.el8_0
Data Computing Appliance (DCA) - update to 4.3.0.0
nspr (Red Hat package) - update to 4.21.0-2.el8_0
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.2.0.5.009
Dell EMC Unity XT Operating Environment (OE) - update to 5.0.2.0.5.009
Dell EMC Unity Operating Environment (OE) - update to 5.0.2.0.5.009

External References

Related Security Bulletins