Heap-based buffer overflow in Mozilla NSS - CVE-2021-43527
Published: December 1, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when handling DER-encoded DSA or RSA-PSS signatures. A remote attacker can send specially crafted signatures encoded within CMS, S/MIME, PKCS #7, or PKCS #12 to the application, trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
RUGGEDCOM ROX RX1500
RUGGEDCOM ROX RX5000
RUGGEDCOM ROX RX1536
RUGGEDCOM ROX RX1524
RUGGEDCOM ROX RX1512
RUGGEDCOM ROX RX1511
RUGGEDCOM ROX RX1510
RUGGEDCOM ROX RX1501
RUGGEDCOM ROX RX1400
RUGGEDCOM ROX MX5000
Fujitsu M12-1
Fujitsu M12-2
Fujitsu M12-2S
Arch Linux
Gentoo Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE MicroOS
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux Server - Extended Life Cycle Support
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems)
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
SUSE Linux Enterprise Storage
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Anolis OS
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
Slackware Linux
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Desktop
openSUSE Leap
openEuler
Fedora
Chrome OS
Fujitsu M10-4S
Fujitsu M10-4
Fujitsu M10-1
Oracle Communications User Data Repository
Oracle Communications Policy Management
Dell EMC PowerStore Family Operating System
XtremIO X2
Oracle Communications Cloud Native Core Network Slice Selection Function
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Network Repository Function
Dell Secure Connect Gateway
Red Hat Advanced Cluster Management for Kubernetes
Session Smart Router
IBM Spectrum Protect Plus
nss (Debian package)
nss (Red Hat package)
redhat-release-virtualization-host (Red Hat package)
redhat-virtualization-host (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
thunderbird (Red Hat package)
libnss3 (Ubuntu package)
nss-softokn
nss-util-devel
nss
nss-util
nss-tools
nss-sysinit
nss-softokn-freebl-devel
nss-softokn-freebl
nss-devel
nss-softokn-devel
nss-help
nss-debugsource
nss-debuginfo
libfreebl3
libfreebl3-debuginfo
libfreebl3-hmac
libsoftokn3-hmac
libsoftokn3
libsoftokn3-debuginfo
mozilla-nss-certs-32bit-debuginfo
mozilla-nss-certs-32bit
mozilla-nss-32bit-debuginfo
mozilla-nss-32bit
libsoftokn3-hmac-32bit
libsoftokn3-32bit-debuginfo
libsoftokn3-32bit
libfreebl3-hmac-32bit
libfreebl3-32bit-debuginfo
libfreebl3-32bit
mozilla-nss-sysinit
mozilla-nss-devel
mozilla-nss-tools-debuginfo
mozilla-nss-tools
mozilla-nss-debugsource
mozilla-nss-debuginfo
mozilla-nss-certs-debuginfo
mozilla-nss-certs
mozilla-nss
mozilla-nss-sysinit-debuginfo
libsoftokn3-debuginfo-32bit
mozilla-nss-debuginfo-32bit
mozilla-nss-sysinit-32bit
mozilla-nss-sysinit-debuginfo-32bit
mozilla-nss-certs-debuginfo-32bit
libfreebl3-debuginfo-32bit
dev-libs/nss
mozilla-nss-sysinit-32bit-debuginfo
mozilla-nspr-debuginfo
mozilla-nspr-devel
mozilla-nspr-32bit
mozilla-nspr
mozilla-nspr-debugsource
mozilla-nspr-debuginfo-32bit
mozilla-nspr-32bit-debuginfo
thunderbird (Ubuntu package)
Red Hat Virtualization
OpenShift Virtualization
Red Hat Virtualization Host
Contrail Networking
Oracle Communications Instant Messaging Server
JD Edwards EnterpriseOne Tools
Red Hat OpenShift Container Platform
Dell EMC Storage Monitoring and Reporting (SMR)
IBM QRadar Network Security
Dell EMC VxRail Appliance
Juniper Junos Space
How to mitigate CVE-2021-43527
RUGGEDCOM ROX RX1500 - update to 2.15.0
RUGGEDCOM ROX RX5000 - update to 2.15.0
RUGGEDCOM ROX RX1536 - update to 2.15.0
RUGGEDCOM ROX RX1524 - update to 2.15.0
RUGGEDCOM ROX RX1512 - update to 2.15.0
RUGGEDCOM ROX RX1511 - update to 2.15.0
RUGGEDCOM ROX RX1510 - update to 2.15.0
RUGGEDCOM ROX RX1501 - update to 2.15.0
RUGGEDCOM ROX RX1400 - update to 2.15.0
RUGGEDCOM ROX MX5000 - update to 2.15.0
nss (Debian package) - addressed in versions 2:3.42.1-1+deb10u4, 2:3.61-1+deb11u1
nss (Red Hat package) - addressed in versions 3.28.4-2.el7_3, 3.28.4-18.el7_4, 3.36.0-10.2.el7_6, 3.44.0-8.el7_7, 3.44.0-10.el8_1, 3.44.0-12.el6_10, 3.53.1-12.el8_2, 3.67.0-4.el7_9, 3.67.0-7.el8_4, 3.67.0-7.el8_5
redhat-release-virtualization-host (Red Hat package) - addressed in versions 4.3.20-1.el7ev, 4.4.9-3.el8ev
redhat-virtualization-host (Red Hat package) - update to 4.3.20-20211202.1.el7_9
OpenShift Virtualization - addressed in versions 4.9.2, 4.11.0
Dell Secure Connect Gateway - update to 5.14.00.10
JD Edwards EnterpriseOne Tools - update to 9.2.6.4
thunderbird (Red Hat package) - addressed in versions 91.3.0-3.el8_1, 91.3.0-3.el8_2
Chrome OS - addressed in versions 96.0.4664.208, 96.0.4664.209
Dell EMC PowerStore Family Operating System - update to 2.1.1.2- 1885194
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
libnss3 (Ubuntu package) - addressed in versions 2:3.28.40ubuntu0.16.04.14+esm1, 2:3.28.40ubuntu0.16.04.14+esm2, 2:3.35-2ubuntu2.13, 2:3.49.1-1ubuntu1.6, 2:3.61-1ubuntu2.1, 2:3.68-1ubuntu1.1
nss-softokn - addressed in versions 3.53.1-12, 3.67.0-7
nss-util-devel - addressed in versions 3.53.1-12, 3.67.0-7
nss - addressed in versions 3.53.1-12, 3.67.0-7
nss-util - addressed in versions 3.53.1-12, 3.67.0-7
nss-tools - addressed in versions 3.53.1-12, 3.67.0-7
nss-sysinit - addressed in versions 3.53.1-12, 3.67.0-7
nss-softokn-freebl-devel - addressed in versions 3.53.1-12, 3.67.0-7
nss-softokn-freebl - addressed in versions 3.53.1-12, 3.67.0-7
nss-devel - addressed in versions 3.53.1-12, 3.67.0-7
nss-softokn-devel - addressed in versions 3.53.1-12, 3.67.0-7
nss - update to 3.54.0-8
nss-softokn-devel - update to 3.54.0-8
nss-util - update to 3.54.0-8
nss-util-devel - update to 3.54.0-8
nss-help - update to 3.54.0-8
nss-devel - update to 3.54.0-8
nss-softokn - update to 3.54.0-8
nss-debugsource - update to 3.54.0-8
nss-debuginfo - update to 3.54.0-8
libfreebl3 - addressed in versions 3.68.1-3.61.1, 3.68.1-47.19.1, 3.68.1-58.57.1, 3.79-58.75.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
libfreebl3-debuginfo - addressed in versions 3.68.1-3.61.1, 3.68.1-58.57.1, 3.79-58.75.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
libfreebl3-hmac - addressed in versions 3.68.1-3.61.1, 3.68.1-58.57.1, 3.79-58.75.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
libsoftokn3-hmac - addressed in versions 3.68.1-3.61.1, 3.68.1-58.57.1, 3.79-58.75.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
libsoftokn3 - addressed in versions 3.68.1-3.61.1, 3.68.1-47.19.1, 3.68.1-58.57.1, 3.79-58.75.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
libsoftokn3-debuginfo - addressed in versions 3.68.1-3.61.1, 3.68.1-58.57.1, 3.79-58.75.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
mozilla-nss-certs-32bit-debuginfo - addressed in versions 3.68.1-3.61.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
mozilla-nss-certs-32bit - addressed in versions 3.68.1-3.61.1, 3.68.1-47.19.1, 3.68.1-58.57.1, 3.79-58.75.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
mozilla-nss-32bit-debuginfo - addressed in versions 3.68.1-3.61.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
mozilla-nss-32bit - addressed in versions 3.68.1-3.61.1, 3.68.1-47.19.1, 3.68.1-58.57.1, 3.79-58.75.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
libsoftokn3-hmac-32bit - addressed in versions 3.68.1-3.61.1, 3.68.1-58.57.1, 3.79-58.75.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
libsoftokn3-32bit-debuginfo - addressed in versions 3.68.1-3.61.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
libsoftokn3-32bit - addressed in versions 3.68.1-3.61.1, 3.68.1-47.19.1, 3.68.1-58.57.1, 3.79-58.75.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
libfreebl3-hmac-32bit - addressed in versions 3.68.1-3.61.1, 3.68.1-58.57.1, 3.79-58.75.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
libfreebl3-32bit-debuginfo - addressed in versions 3.68.1-3.61.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
libfreebl3-32bit - addressed in versions 3.68.1-3.61.1, 3.68.1-47.19.1, 3.68.1-58.57.1, 3.79-58.75.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
mozilla-nss-sysinit - addressed in versions 3.68.1-3.61.1, 3.68.1-58.57.1, 3.79-58.75.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
mozilla-nss-devel - addressed in versions 3.68.1-3.61.1, 3.68.1-47.19.1, 3.68.1-58.57.1, 3.79-58.75.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
mozilla-nss-tools-debuginfo - addressed in versions 3.68.1-3.61.1, 3.68.1-58.57.1, 3.79-58.75.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
mozilla-nss-tools - addressed in versions 3.68.1-3.61.1, 3.68.1-47.19.1, 3.68.1-58.57.1, 3.79-58.75.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
mozilla-nss-debugsource - addressed in versions 3.68.1-3.61.1, 3.68.1-58.57.1, 3.79-58.75.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
mozilla-nss-debuginfo - addressed in versions 3.68.1-3.61.1, 3.68.1-47.19.1, 3.68.1-58.57.1, 3.79-58.75.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
mozilla-nss-certs-debuginfo - addressed in versions 3.68.1-3.61.1, 3.68.1-58.57.1, 3.79-58.75.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
mozilla-nss-certs - addressed in versions 3.68.1-3.61.1, 3.68.1-47.19.1, 3.68.1-58.57.1, 3.79-58.75.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
mozilla-nss - addressed in versions 3.68.1-3.61.1, 3.68.1-47.19.1, 3.68.1-58.57.1, 3.79-58.75.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
mozilla-nss-sysinit-debuginfo - addressed in versions 3.68.1-3.61.1, 3.68.1-58.57.1, 3.79-58.75.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
libsoftokn3-debuginfo-32bit - addressed in versions 3.68.1-58.57.1, 3.79-58.75.1
mozilla-nss-debuginfo-32bit - addressed in versions 3.68.1-58.57.1, 3.79-58.75.1
mozilla-nss-sysinit-32bit - addressed in versions 3.68.1-58.57.1, 3.79-58.75.1, 3.79-150000.3.74.1, 3.79-150400.3.7.1
mozilla-nss-sysinit-debuginfo-32bit - addressed in versions 3.68.1-58.57.1, 3.79-58.75.1
mozilla-nss-certs-debuginfo-32bit - addressed in versions 3.68.1-58.57.1, 3.79-58.75.1
libfreebl3-debuginfo-32bit - addressed in versions 3.68.1-58.57.1, 3.79-58.75.1
nss - addressed in versions 3.73.0-1.fc34, 3.73.0-1.fc35
dev-libs/nss - update to 3.79.2
mozilla-nss-sysinit-32bit-debuginfo - addressed in versions 3.79-150000.3.74.1, 3.79-150400.3.7.1
nss - update to 3.83.0-1
mozilla-nss - update to 3.87
Red Hat OpenShift Container Platform - addressed in versions 4.7.40, 4.11.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.8.0.0
mozilla-nspr-debuginfo - addressed in versions 4.34-19.21.1, 4.34-150000.3.23.1
mozilla-nspr-devel - addressed in versions 4.34-19.21.1, 4.34-150000.3.23.1
mozilla-nspr-32bit - addressed in versions 4.34-19.21.1, 4.34-150000.3.23.1
mozilla-nspr - addressed in versions 4.34-19.21.1, 4.34-150000.3.23.1
mozilla-nspr-debugsource - addressed in versions 4.34-19.21.1, 4.34-150000.3.23.1
mozilla-nspr-debuginfo-32bit - update to 4.34-19.21.1
mozilla-nspr-32bit-debuginfo - update to 4.34-150000.3.23.1
IBM QRadar Network Security - addressed in versions 5.4.0.17, 5.5.0.12
Session Smart Router - addressed in versions 5.4.7, 5.5.3
XtremIO X2 - update to 6.4.2-13
Dell EMC VxRail Appliance - update to 8.0.000
IBM Spectrum Protect Plus - update to 10.1.10
Juniper Junos Space - update to 22.2R1
thunderbird (Ubuntu package) - addressed in versions 1:78.14.0+build1-0ubuntu0.18.04.2, 1:78.14.0+build1-0ubuntu0.20.04.2, 1:78.14.0+build1-0ubuntu0.21.04.2, 1:91.3.1+build1-0ubuntu0.21.10.2
Contrail Networking - update to 2011.L5
External References
Related Security Bulletins
- Remote code execution in Mozilla NSS
- Red Hat Enterprise Linux 8 update for nss
- Amazon Linux AMI update for nss
- Red Hat Enterprise Linux 8.2 update for nss
- Red Hat Enterprise Linux 8.4 update for nss
- Red Hat Enterprise Linux 6 Extended Lifecycle Support update for nss
- Red Hat Enterprise Linux 7 update for nss
- Arch Linux update for lib32-nss
- Arch Linux update for nss
- Slackware Linux update for mozilla-nss
- Red Hat Enterprise Linux 7.4 update for nss
- Red Hat Enterprise Linux 7.6 update for nss
- Red Hat Enterprise Linux 7.7 update for nss
- Debian update for nss
- Red Hat Enterprise Linux 8.1 update for nss
- Red Hat Enterprise Linux 8.2 update for thunderbird
- Red Hat Enterprise Linux 8.1 update for thunderbird
- Red Hat Enterprise Linux 7.3 update for nss
- Red Hat Virtualization update for nss
- Red Hat Virtualization 4 update for redhat-release-virtualization-host and redhat-virtualization-host
- Multiple vulnerabilities in Red Hat OpenShift Virtualization
- Remote code execution in Siemens RUGGEDCOM ROX products
- Multiple vulnerabilities in Oracle Communications Policy Management
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Repository Function
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Slice Selection Function
- Multiple vulnerabilities in Google ChromeOS
- Multiple vulnerabilities in Google ChromeOS
- SUSE update for mozilla-nss
- SUSE update for mozilla-nss
- SUSE update for mozilla-nss
- Ubuntu update for nss
- Ubuntu update for nss
- Ubuntu update for thunderbird
- Ubuntu update for nss
- SUSE update for mozilla-nss
- SUSE update for mozilla-nspr, mozilla-nss
- SUSE update for mozilla-nss
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in OpenShift Virtualization
- Multiple vulnerabilities in Juniper Networks Contrail Networking
- Multiple vulnerabilities in Junos Space
- Multiple vulnerabilities in Juniper Networks Session Smart Router
- Multiple vulnerabilities in Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Oracle Communications User Data Repository
- Heap-based buffer overflow in Oracle Communications Messaging Server
- Multiple vulnerabilities in JD Edwards EnterpriseOne Tools
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Gentoo update for Mozilla Network Security Service (NSS)
- Multiple vulnerabilities in IBM QRadar Network Security
- Multiple vulnerabilities in Dell PowerStore Family
- Slackware Linux update for mozilla-nss
- Multiple vulnerabilities in Dell VxRail Appliance components
- Multiple vulnerabilities in Fujitsu M12-2S
- Multiple vulnerabilities in Fujitsu M12-2
- Multiple vulnerabilities in Fujitsu M12-1
- Multiple vulnerabilities in Fujitsu M10-4S
- Multiple vulnerabilities in Fujitsu M10-4
- Multiple vulnerabilities in Fujitsu M10-1
- openEuler update for nss
- Amazon Linux AMI update for nss
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.7
- Fedora 35 update for nss
- Fedora 34 update for nss
- Multiple vulnerabilities in Dell XtremIO X2
- IBM Spectrum Protect Plus update for Mozilla Network Security Services (NSS)
- Anolis OS update for nss (Anolis OS 8.2)
- Anolis OS update for nss (Anolis OS 8.4)
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.2