Stack-based buffer overflow in Mozilla NSS - CVE-2022-3479
Published: November 4, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error within the NSS_GetClientAuthData() function in /lib/ssl/authcert.c when accessing gnutls server without a user certificate in the database. A remote attacker can trigger a stack-based buffer overflow and crash the application using the affected library.
Affected software
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
Slackware Linux
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
Ubuntu
openEuler
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
PowerStore T
Dell EMC PowerStore Family Operating System
EMC Cloud Tiering Appliance
Oracle Healthcare Translational Research
Oracle Communications Instant Messaging Server
JD Edwards EnterpriseOne Tools
HPE Moonshot 1500 Chassis Manager
libnss3 (Ubuntu package)
dev-libs/nss
libfreebl3-hmac
libfreebl3-debuginfo-32bit
libfreebl3
libfreebl3-32bit
libfreebl3-debuginfo
mozilla-nss-tools-debuginfo
mozilla-nss-tools
mozilla-nss-sysinit-debuginfo-32bit
mozilla-nss-sysinit-debuginfo
mozilla-nss-sysinit-32bit
mozilla-nss-sysinit
mozilla-nss-devel
mozilla-nss-debugsource
mozilla-nss-debuginfo-32bit
mozilla-nss-debuginfo
mozilla-nss-certs-debuginfo
mozilla-nss-certs-debuginfo-32bit
libfreebl3-hmac-32bit
libsoftokn3
libsoftokn3-32bit
libsoftokn3-debuginfo
libsoftokn3-debuginfo-32bit
libsoftokn3-hmac
libsoftokn3-hmac-32bit
mozilla-nss
mozilla-nss-32bit
mozilla-nss-certs
mozilla-nss-certs-32bit
libfreebl3-32bit-debuginfo
libsoftokn3-32bit-debuginfo
mozilla-nss-32bit-debuginfo
mozilla-nss-certs-32bit-debuginfo
mozilla-nss-sysinit-32bit-debuginfo
firefox
firefox-debugsource
firefox-debuginfo
RecoverPoint for VMs
Dell EMC VxRail Appliance
How to mitigate CVE-2022-3479
JD Edwards EnterpriseOne Tools - update to 9.2.8.0
PowerStore T - update to 3.5.0.1-2083289
libnss3 (Ubuntu package) - addressed in versions 2:3.35-2ubuntu2.16, 2:3.49.1-1ubuntu1.9, 2:3.68.2-0ubuntu1.2, 2:3.82-1ubuntu0.1
dev-libs/nss - update to 3.79.2
libfreebl3-hmac - addressed in versions 3.79.3-58.91.1, 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
libfreebl3-debuginfo-32bit - update to 3.79.3-58.91.1
libfreebl3 - addressed in versions 3.79.3-58.91.1, 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
libfreebl3-32bit - addressed in versions 3.79.3-58.91.1, 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
libfreebl3-debuginfo - addressed in versions 3.79.3-58.91.1, 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
mozilla-nss-tools-debuginfo - addressed in versions 3.79.3-58.91.1, 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
mozilla-nss-tools - addressed in versions 3.79.3-58.91.1, 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
mozilla-nss-sysinit-debuginfo-32bit - update to 3.79.3-58.91.1
mozilla-nss-sysinit-debuginfo - addressed in versions 3.79.3-58.91.1, 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
mozilla-nss-sysinit-32bit - addressed in versions 3.79.3-58.91.1, 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
mozilla-nss-sysinit - addressed in versions 3.79.3-58.91.1, 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
mozilla-nss-devel - addressed in versions 3.79.3-58.91.1, 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
mozilla-nss-debugsource - addressed in versions 3.79.3-58.91.1, 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
mozilla-nss-debuginfo-32bit - update to 3.79.3-58.91.1
mozilla-nss-debuginfo - addressed in versions 3.79.3-58.91.1, 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
mozilla-nss-certs-debuginfo - addressed in versions 3.79.3-58.91.1, 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
mozilla-nss-certs-debuginfo-32bit - update to 3.79.3-58.91.1
libfreebl3-hmac-32bit - addressed in versions 3.79.3-58.91.1, 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
libsoftokn3 - addressed in versions 3.79.3-58.91.1, 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
libsoftokn3-32bit - addressed in versions 3.79.3-58.91.1, 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
libsoftokn3-debuginfo - addressed in versions 3.79.3-58.91.1, 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
libsoftokn3-debuginfo-32bit - update to 3.79.3-58.91.1
libsoftokn3-hmac - addressed in versions 3.79.3-58.91.1, 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
libsoftokn3-hmac-32bit - addressed in versions 3.79.3-58.91.1, 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
mozilla-nss - addressed in versions 3.79.3-58.91.1, 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
mozilla-nss-32bit - addressed in versions 3.79.3-58.91.1, 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
mozilla-nss-certs - addressed in versions 3.79.3-58.91.1, 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
mozilla-nss-certs-32bit - addressed in versions 3.79.3-58.91.1, 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
libfreebl3-32bit-debuginfo - addressed in versions 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
libsoftokn3-32bit-debuginfo - addressed in versions 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
mozilla-nss-32bit-debuginfo - addressed in versions 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
mozilla-nss-certs-32bit-debuginfo - addressed in versions 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
mozilla-nss-sysinit-32bit-debuginfo - addressed in versions 3.79.3-150000.3.90.1, 3.79.3-150400.3.23.1
mozilla-nss - update to 3.84
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
Dell EMC PowerStore Family Operating System - update to 4.0.0.0-2284811
RecoverPoint for VMs - update to 6.0.SP1.P1
Dell EMC VxRail Appliance - update to 7.0.411
EMC Cloud Tiering Appliance - update to 13.2.0.2.22
firefox - update to 102.15.0-5
firefox-debugsource - update to 102.15.0-5
firefox-debuginfo - update to 102.15.0-5
External References
Related Security Bulletins
- Denial of service in Mozilla NSS
- Slackware Linux update for mozilla-nss
- Gentoo update for Mozilla Network Security Service (NSS)
- SUSE update for mozilla-nss
- SUSE update for mozilla-nss
- SUSE update for mozilla-nss
- Ubuntu update for nss
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in Oracle Healthcare Translational Research
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Multiple vulnerabilities in Oracle Communications Messaging Server
- Multiple vulnerabilities in Dell Data Protection Central
- Multiple vulnerabilities in Dell PowerStore Family
- Multiple vulnerabilities in JD Edwards EnterpriseOne Tools
- openEuler 22.03 LTS update for firefox
- openEuler 22.03 LTS SP1 update for firefox
- openEuler 22.03 LTS SP2 update for firefox
- openEuler 22.03 LTS SP3 update for firefox
- Multiple vulnerabilities in Dell PowerStore Family
- Multiple vulnerabilities in HPE Moonshot 1500 Chassis Manager
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines