Main entrypoint for decoding DER blobs in NSS, CERT_DecodeCertPackage() mishandles old Netscape Certificate Sequences, with possible crash as NULL pointer is dereferenced, leading to DoS. External References: https://bugs.chromium.org/p/project-zero/issues/detail?id=1798
Created nss tracking bugs for this issue: Affects: fedora-all [bug 1703987]
Upstream commit: https://hg.mozilla.org/projects/nss/rev/1473dd7efe2ce4f8722a33ebb03a3425e09887de
This vulnerability is out of security support scope for the following product: * Red Hat Enterprise Application Platform 6 Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.
Upstream bug: https://bugzilla.mozilla.org/show_bug.cgi?id=1533216
This issue was addressed via upstream nss-3.44, which is already shipped with Red Hat Enterprise Linux 6, 7 and 8.
Statement: This issue was addressed via upstream nss-3.44, which is already shipped with Red Hat Enterprise Linux 6, 7 and 8.
This issue has been addressed in the following products: Red Hat Enterprise Linux 7.6 Extended Update Support Via RHSA-2021:0876 https://access.redhat.com/errata/RHSA-2021:0876