Name
nss
Version
3.125
Type
library
Description
Mozilla's SSL and TLS implementation
Licenses
(MPL-2.0 & MIT) | (MPL-2.0 & GPL-2.0-or-later & MIT) | (MPL-2.0 & LGPL-2.1-or-later & MIT)
PURL
-
CPE
cpe:2.3:*:*:network_security_services:3.125:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
kirkstone
3.74
scarthgap
3.98

Patches#


#
Title
Author
Resolve
1
nss: does not build on mips with clang because wrong types
Khem Raj <raj.khem@gmail.com>
2
nss: disable Wvarargs with clang
Khem Raj <raj.khem@gmail.com>
3
nss: fix incorrect shebang of perl
Ovidiu Panait <ovidiu.panait@windriver.com>
4
freebl: add a configure option to disable ARM HW crypto
Alexander Kanavin <alex.kanavin@gmail.com>
5
nss:no rpath for cross compiling
Hongxu Jia <hongxu.jia@windriver.com>
6
Fix nss multilib build on openSUSE 11.x 32bit
Wenzong Fan <wenzong.fan@windriver.com>
7
nss: fix support cross compiling
Alexander Kanavin <alex.kanavin@gmail.com>

Vulnerabilities#


Name
Analysis
Description
False Positive
A vulnerability found in nss. By this security vulnerability, nss client auth crash without a user certificate in the database and this can lead us to a segmentation fault or crash.
False Positive
Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.
False Positive
The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS) allows context-dependent attackers to cause a denial of service (floating point exception and crash) via a crafted cert8.db file.
False Positive
Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.
False Positive
Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.