CVE-2017-7502

Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote attacker.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:network_security_services:3.24.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:network_security_services:3.25.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:network_security_services:3.25.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:network_security_services:3.26.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:network_security_services:3.26.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:network_security_services:3.27.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:network_security_services:3.27.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:network_security_services:3.27.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:network_security_services:3.28.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:network_security_services:3.28.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:network_security_services:3.28.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:network_security_services:3.28.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:network_security_services:3.29.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:network_security_services:3.29.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:network_security_services:3.29.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:network_security_services:3.29.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:network_security_services:3.30.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:network_security_services:3.30.1:*:*:*:*:*:*:*

History

12 Feb 2023, 23:30

Type Values Removed Values Added
Summary A null pointer dereference flaw was found in the way NSS handled empty SSLv2 messages. An attacker could use this flaw to crash a server application compiled against the NSS library. Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote attacker.
References
  • {'url': 'https://access.redhat.com/security/cve/CVE-2017-7502', 'name': 'https://access.redhat.com/security/cve/CVE-2017-7502', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1446631', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1446631', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 15:17

Type Values Removed Values Added
References
  • (MISC) https://access.redhat.com/security/cve/CVE-2017-7502 -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1446631 -
Summary Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote attacker. A null pointer dereference flaw was found in the way NSS handled empty SSLv2 messages. An attacker could use this flaw to crash a server application compiled against the NSS library.

Information

Published : 2017-05-30 18:29

Updated : 2023-12-10 12:15


NVD link : CVE-2017-7502

Mitre link : CVE-2017-7502

CVE.ORG link : CVE-2017-7502


JSON object : View

Products Affected

mozilla

  • network_security_services
CWE
CWE-476

NULL Pointer Dereference