Name
nss
Version
3.74
Type
library
Description
Mozilla's SSL and TLS implementation
Licenses
(MPL-2.0 & MIT) | (MPL-2.0 & GPL-2.0-or-later & MIT) | (MPL-2.0 & LGPL-2.1-or-later & MIT)
PURL
-
CPE
cpe:2.3:*:*:network_security_services:3.74:*:*:*:*:*:*:*
Other Versions#
Patches#
#
Title
Author
Resolve
1
Bug 1867408 - add a defensive check for large ssl_DefSend
John Schanck <jschanck@mozilla.com>
CVE-2024-0743
2
nss: fix incorrect shebang of perl
Ovidiu Panait <ovidiu.panait@windriver.com>
3
nss,nspr: Add recipes
Khem Raj <raj.khem@gmail.com>
4
nss:no rpath for cross compiling
Hongxu Jia <hongxu.jia@windriver.com>
5
nss does not build on mips with clang because wrong types are
Khem Raj <raj.khem@gmail.com>
6
Bug 1895032 - remove redundant AllocItem implementation.
John Schanck <jschanck@mozilla.com>
CVE-2024-6602
7
Patch #7
Vivek Kumbhar <vkumbhar@mvista.com>
CVE-2023-0767
8
Fix nss multilib build on openSUSE 11.x 32bit
Wenzong Fan <wenzong.fan@windriver.com>
9
Bug 1750624 - Pin validation date for PayPalEE test cert.
"John M. Schanck" <jschanck@mozilla.com>
10
freebl: add a configure option to disable ARM HW crypto
Alexander Kanavin <alex.kanavin@gmail.com>
11
Bug 1780432 (CVE-2023-5388) Timing attack against RSA
Robert Relyea <rrelyea@redhat.com>
CVE-2023-5388
12
fix CVE-2024-6609
Peter Marko <peter.marko@siemens.com>
CVE-2024-6609
13
nss: fix support cross compiling
Alexander Kanavin <alex.kanavin@gmail.com>
Vulnerabilities#
Name
Analysis
Description
Patched
When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerability affects Firefox < 128 and Thunderbird < 128.
Patched
A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
Patched
An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.9, and Thunderbird < 115.9.
Patched
NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
Patched
An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mishandled. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.