A NULL pointer dereference issue was found in several CMS function. A specially crafted data could possibly crash nss. External References: https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.41.1_release_notes
Created nss tracking bugs for this issue: Affects: fedora-all [bug 1671311]
Upstream patch: https://hg.mozilla.org/projects/nss/rev/08d1b0c1117f https://hg.mozilla.org/projects/nss/rev/5e70b72131ac
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2019:1951 https://access.redhat.com/errata/RHSA-2019:1951
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2018-18508
Mitigation: This issue only affects applications compiled against NSS which use CMS (Cryptographic Message Syntax) API. Other applications are not affected.