Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 676868 (CVE-2018-18508) - <dev-libs/nss-3.41-r1: NULL pointer dereference in several CMS functions resulting in a denial of service (CVE-2018-18508)
Summary: <dev-libs/nss-3.41-r1: NULL pointer dereference in several CMS functions resu...
Status: RESOLVED FIXED
Alias: CVE-2018-18508
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://developer.mozilla.org/en-US/d...
Whiteboard: A3 [glsa+ cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2019-01-29 22:02 UTC by Hanno Böck
Modified: 2020-03-16 21:19 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Hanno Böck gentoo-dev 2019-01-29 22:02:28 UTC
nss 3.41.1 fixes a pretty nasty DoS issue due to a NULL pointer deref. This is particularly worrying for Thunderbird, because you can send a mail to someone that will make TB unusable, it will crash on every startup. (I have a poc, but will wait some time until I share it publicly.

Please bump.
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2020-03-15 15:27:33 UTC
New GLSA request filed.
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2020-03-16 21:19:30 UTC
This issue was resolved and addressed in
 GLSA 202003-37 at https://security.gentoo.org/glsa/202003-37
by GLSA coordinator Thomas Deutschmann (whissi).