CVE-2022-3479

NameCVE-2022-3479
DescriptionA vulnerability found in nss. By this security vulnerability, nss client auth crash without a user certificate in the database and this can lead us to a segmentation fault or crash.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)
Debian Bugs1021786

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nss (PTS)buster, buster (security)2:3.42.1-1+deb10u5fixed
bullseye (security), bullseye2:3.61-1+deb11u2vulnerable
bookworm, sid2:3.85-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nsssourcebuster(not affected)
nsssource(unstable)(unfixed)1021786

Notes

[bullseye] - nss <no-dsa> (Minor issue)
[buster] - nss <not-affected> (The vulnerable code was introduced later)
https://bugzilla.mozilla.org/show_bug.cgi?id=1774654

Search for package or bug name: Reporting problems