Bug 1124571 - (CVE-2018-18508) VUL-0: CVE-2018-18508: mozilla-nss: NULL pointer dereference in several CMS functions resulting in a denial of service
(CVE-2018-18508)
VUL-0: CVE-2018-18508: mozilla-nss: NULL pointer dereference in several CMS f...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/224360/
CVSSv3:RedHat:CVE-2018-18508:6.5:(AV:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-02-07 07:34 UTC by Marcus Meissner
Modified: 2019-11-14 15:39 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2019-02-07 07:34:04 UTC
rh#1671310


A NULL pointer dereference issue was found in several CMS function. A specially crafted data could possibly crash nss.

External References:

https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.41.1_release_notes

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1671310
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-18508