Input validation error in Mozilla NSS - CVE-2019-11729
Published: December 12, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when processing an empty or malformed p256-ECDH public keys. A remote attacker can trigger a segmentation fault and cause a denial of service condition on the target system.
Affected software
SUSE Package Hub for SUSE Linux Enterprise
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Slackware Linux
Opensuse
Secure Remote Services (SRS) Virtual Edition
Data Computing Appliance (DCA)
firefox-esr (Alpine package)
nss (Red Hat package)
nspr (Red Hat package)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
How to mitigate CVE-2019-11729
Secure Remote Services (SRS) Virtual Edition - update to 3.46.00.04
firefox-esr (Alpine package) - update to 60.8.0-r0
nss (Red Hat package) - update to 3.44.0-7.el8_0
Data Computing Appliance (DCA) - update to 4.3.0.0
nspr (Red Hat package) - update to 4.21.0-2.el8_0
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.2.0.5.009
Dell EMC Unity XT Operating Environment (OE) - update to 5.0.2.0.5.009
Dell EMC Unity Operating Environment (OE) - update to 5.0.2.0.5.009
External References
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00055.html
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00058.html
- https://access.redhat.com/errata/RHSA-2019:1951
- https://bugzilla.mozilla.org/show_bug.cgi?id=1515342
- https://www.mozilla.org/security/advisories/mfsa2019-21/
- https://www.mozilla.org/security/advisories/mfsa2019-22/
- https://www.mozilla.org/security/advisories/mfsa2019-23/
Related Security Bulletins
- Denial of service in Mozilla NSS
- RHSA-2019:4190 - Security Advisory
- Amazon Linux AMI update for nss, nss-softokn, nss-util, nspr
- OpenSUSE Linux update for MozillaThunderbird
- OpenSUSE Linux update for MozillaThunderbird
- OpenSUSE Linux update for MozillaFirefox
- OpenSUSE Linux update for MozillaFirefox
- Input validation error in firefox-esr (Alpine package)
- Gentoo update for Mozilla Thunderbird
- Slackware Linux update for mozilla-firefox
- Multiple vulnerabilities in Dell EMC Secure Remote Services (SRS) Virtual Edition
- Multiple vulnerabilities in Dell EMC Unity Family, Dell EMC Unity XT Family
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Red Hat Enterprise Linux 8 update for nss and nspr