Lucene search

K
ubuntuUbuntuUSN-5872-1
HistoryFeb 15, 2023 - 12:00 a.m.

NSS vulnerabilities

2023-02-1500:00:00
ubuntu.com
39
nss
ubuntu
esm
vulnerabilities
tavis ormandy
ronald crane
cve-2022-22747
cve-2022-34480
denial of service
arbitrary code
memory operations

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

9.3 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.3%

Releases

  • Ubuntu 16.04 ESM
  • Ubuntu 14.04 ESM

Packages

  • nss - Network Security Service library

Details

Tavis Ormandy discovered that NSS incorrectly handled an empty pkcs7
sequence. A remote attacker could possibly use this issue to cause NSS to
crash, resulting in a denial of service. (CVE-2022-22747)

Ronald Crane discovered that NSS incorrectly handled certain memory
operations. A remote attacker could use this issue to cause NSS to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2022-34480)

OSVersionArchitecturePackageVersionFilename
Ubuntu16.04noarchlibnss3< 2:3.28.4-0ubuntu0.16.04.14+esm3UNKNOWN
Ubuntu16.04noarchlibnss3< 2:3.28.4-0ubuntu0.16.04.14UNKNOWN
Ubuntu16.04noarchlibnss3-1d< 2:3.28.4-0ubuntu0.16.04.14UNKNOWN
Ubuntu16.04noarchlibnss3-dbg< 2:3.28.4-0ubuntu0.16.04.14UNKNOWN
Ubuntu16.04noarchlibnss3-dbgsym< 2:3.28.4-0ubuntu0.16.04.14UNKNOWN
Ubuntu16.04noarchlibnss3-dev< 2:3.28.4-0ubuntu0.16.04.14UNKNOWN
Ubuntu16.04noarchlibnss3-nssdb< 2:3.28.4-0ubuntu0.16.04.14UNKNOWN
Ubuntu16.04noarchlibnss3-tools< 2:3.28.4-0ubuntu0.16.04.14UNKNOWN
Ubuntu16.04noarchlibnss3-tools-dbgsym< 2:3.28.4-0ubuntu0.16.04.14UNKNOWN
Ubuntu14.04noarchlibnss3< 2:3.28.4-0ubuntu0.14.04.5+esm11UNKNOWN
Rows per page:
1-10 of 171

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

9.3 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.3%