Lucene search

K
ibmIBM1352CEBCFF6DCCE9DDB15F8069CB46F252AFDC38A9B79AF55C83340B29AE6CEB
HistorySep 22, 2021 - 11:38 p.m.

Security Bulletin: Vulnerability in nss and nspr CVE-2019-17006.

2021-09-2223:38:15
www.ibm.com
16

0.004 Low

EPSS

Percentile

73.6%

Summary

Network Security Services (NSS) & Netscape Portable Runtime (NSPR) is used by Power Hardware Management Console (HMC). HMC has addressed the applicable CVE.

Vulnerability Details

CVEID:CVE-2019-17006
**DESCRIPTION:**Mozilla Network Security Services (NSS), as used in Mozilla Firefox is vulnerable to a heap-based buffer overflow, caused by improper bounds checking when using certain cryptographic primitives. By sending an overly long argument, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause a denial of service.
CVSS Base score: 8.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/174125 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
HMC V9.1.910.0 V9.1.910.0

Remediation/Fixes

Remediation/Fixes

The following fixes are available on IBM Fix Central at: <http://www-933.ibm.com/support/fixcentral/&gt;

Product

|

VRMF

|

APAR

|

Remediation/Fix

—|—|—|—

Power HMC

|

V9.1.940.0 SP2 ppc

|

MB04269

|

MH01877

Power HMC

|

V9.1.940.0 SP2 x86_64

|

MB04268

|

MH01876

Workarounds and Mitigations

None