Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 676868 (CVE-2018-18508)

Summary: <dev-libs/nss-3.41-r1: NULL pointer dereference in several CMS functions resulting in a denial of service (CVE-2018-18508)
Product: Gentoo Security Reporter: Hanno Böck <hanno>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal    
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.41.1_release_notes
Whiteboard: A3 [glsa+ cve]
Package list:
Runtime testing required: ---

Description Hanno Böck gentoo-dev 2019-01-29 22:02:28 UTC
nss 3.41.1 fixes a pretty nasty DoS issue due to a NULL pointer deref. This is particularly worrying for Thunderbird, because you can send a mail to someone that will make TB unusable, it will crash on every startup. (I have a poc, but will wait some time until I share it publicly.

Please bump.
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2020-03-15 15:27:33 UTC
New GLSA request filed.
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2020-03-16 21:19:30 UTC
This issue was resolved and addressed in
 GLSA 202003-37 at https://security.gentoo.org/glsa/202003-37
by GLSA coordinator Thomas Deutschmann (whissi).