nss is vulnerable to denial of service (DoS). The vulnerability exists through empty or malformed p256-ECDH public keys may trigger a segmentation fault.
lists.opensuse.org/opensuse-security-announce/2019-07/msg00055.html
lists.opensuse.org/opensuse-security-announce/2019-07/msg00058.html
lists.opensuse.org/opensuse-security-announce/2019-08/msg00073.html
lists.opensuse.org/opensuse-security-announce/2019-10/msg00009.html
lists.opensuse.org/opensuse-security-announce/2019-10/msg00010.html
access.redhat.com/errata/RHSA-2019:1951
access.redhat.com/errata/RHSA-2019:4190
access.redhat.com/security/updates/classification/#important
bugzilla.mozilla.org/show_bug.cgi?id=1515342
lists.debian.org/debian-lts-announce/2020/09/msg00029.html
security.gentoo.org/glsa/201908-12
security.gentoo.org/glsa/201908-20
www.mozilla.org/security/advisories/mfsa2019-21/
www.mozilla.org/security/advisories/mfsa2019-22/
www.mozilla.org/security/advisories/mfsa2019-23/