Search

Find a vulnerability

Search criteria

    Related vulnerabilities

    USN-5892-1 (UBUNTU-CVE-2022-3479)

    Vulnerability from osv_ubuntu – Published: 2023-02-27 12:44 – Updated: 2026-04-22 07:37 – Source website
    VLAI
    Summary
    nss vulnerabilities
    Details

    It was discovered that NSS incorrectly handled client authentication without a user certificate in the database. A remote attacker could possibly use this issue to cause a NSS client to crash, resulting in a denial of service. This issue only affected Ubuntu 22.10. (CVE-2022-3479)

    Christian Holler discovered that NSS incorrectly handled certain PKCS 12 certificated bundles. A remote attacker could use this issue to cause NSS to crash, leading to a denial of service, or possibly execute arbitrary code. (CVE-2023-0767)


    {
      "affected": [
        {
          "database_specific": {
            "cves_map": {
              "cves": [
                {
                  "id": "CVE-2023-0767",
                  "severity": [
                    {
                      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                      "type": "CVSS_V3"
                    },
                    {
                      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                      "type": "CVSS_V3"
                    },
                    {
                      "score": "medium",
                      "type": "Ubuntu"
                    }
                  ]
                }
              ],
              "ecosystem": "Ubuntu:18.04:LTS"
            }
          },
          "ecosystem_specific": {
            "availability": "No subscription required",
            "binaries": [
              {
                "binary_name": "libnss3",
                "binary_version": "2:3.35-2ubuntu2.16"
              },
              {
                "binary_name": "libnss3-tools",
                "binary_version": "2:3.35-2ubuntu2.16"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:18.04:LTS",
            "name": "nss",
            "purl": "pkg:deb/ubuntu/nss@2:3.35-2ubuntu2.16?arch=source\u0026distro=bionic"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2:3.35-2ubuntu2.16"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2:3.32-1ubuntu3",
            "2:3.34-1ubuntu1",
            "2:3.35-2ubuntu2",
            "2:3.35-2ubuntu2.1",
            "2:3.35-2ubuntu2.2",
            "2:3.35-2ubuntu2.3",
            "2:3.35-2ubuntu2.5",
            "2:3.35-2ubuntu2.6",
            "2:3.35-2ubuntu2.7",
            "2:3.35-2ubuntu2.8",
            "2:3.35-2ubuntu2.9",
            "2:3.35-2ubuntu2.11",
            "2:3.35-2ubuntu2.12",
            "2:3.35-2ubuntu2.13",
            "2:3.35-2ubuntu2.14",
            "2:3.35-2ubuntu2.15"
          ]
        },
        {
          "database_specific": {
            "cves_map": {
              "cves": [
                {
                  "id": "CVE-2023-0767",
                  "severity": [
                    {
                      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                      "type": "CVSS_V3"
                    },
                    {
                      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                      "type": "CVSS_V3"
                    },
                    {
                      "score": "medium",
                      "type": "Ubuntu"
                    }
                  ]
                }
              ],
              "ecosystem": "Ubuntu:20.04:LTS"
            }
          },
          "ecosystem_specific": {
            "availability": "No subscription required",
            "binaries": [
              {
                "binary_name": "libnss3",
                "binary_version": "2:3.49.1-1ubuntu1.9"
              },
              {
                "binary_name": "libnss3-tools",
                "binary_version": "2:3.49.1-1ubuntu1.9"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:20.04:LTS",
            "name": "nss",
            "purl": "pkg:deb/ubuntu/nss@2:3.49.1-1ubuntu1.9?arch=source\u0026distro=focal"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2:3.49.1-1ubuntu1.9"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2:3.45-1ubuntu2",
            "2:3.47-1ubuntu1",
            "2:3.47-1ubuntu2",
            "2:3.48-1ubuntu1",
            "2:3.49.1-1ubuntu1",
            "2:3.49.1-1ubuntu1.1",
            "2:3.49.1-1ubuntu1.2",
            "2:3.49.1-1ubuntu1.4",
            "2:3.49.1-1ubuntu1.5",
            "2:3.49.1-1ubuntu1.6",
            "2:3.49.1-1ubuntu1.7",
            "2:3.49.1-1ubuntu1.8"
          ]
        },
        {
          "database_specific": {
            "cves_map": {
              "cves": [
                {
                  "id": "CVE-2023-0767",
                  "severity": [
                    {
                      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                      "type": "CVSS_V3"
                    },
                    {
                      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                      "type": "CVSS_V3"
                    },
                    {
                      "score": "medium",
                      "type": "Ubuntu"
                    }
                  ]
                }
              ],
              "ecosystem": "Ubuntu:22.04:LTS"
            }
          },
          "ecosystem_specific": {
            "availability": "No subscription required",
            "binaries": [
              {
                "binary_name": "libnss3",
                "binary_version": "2:3.68.2-0ubuntu1.2"
              },
              {
                "binary_name": "libnss3-tools",
                "binary_version": "2:3.68.2-0ubuntu1.2"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:22.04:LTS",
            "name": "nss",
            "purl": "pkg:deb/ubuntu/nss@2:3.68.2-0ubuntu1.2?arch=source\u0026distro=jammy"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "2:3.68.2-0ubuntu1.2"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "2:3.68-1ubuntu1",
            "2:3.68-1ubuntu2",
            "2:3.68.2-0ubuntu1",
            "2:3.68.2-0ubuntu1.1"
          ]
        }
      ],
      "aliases": [],
      "details": "It was discovered that NSS incorrectly handled client authentication\nwithout a user certificate in the database. A remote attacker could\npossibly use this issue to cause a NSS client to crash, resulting in a\ndenial of service. This issue only affected Ubuntu 22.10. (CVE-2022-3479)\n\nChristian Holler discovered that NSS incorrectly handled certain PKCS 12\ncertificated bundles. A remote attacker could use this issue to cause NSS\nto crash, leading to a denial of service, or possibly execute arbitrary\ncode. (CVE-2023-0767)\n",
      "id": "USN-5892-1",
      "modified": "2026-04-22T07:37:04Z",
      "published": "2023-02-27T12:44:07Z",
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://ubuntu.com/security/notices/USN-5892-1"
        },
        {
          "type": "REPORT",
          "url": "https://ubuntu.com/security/CVE-2022-3479"
        },
        {
          "type": "REPORT",
          "url": "https://ubuntu.com/security/CVE-2023-0767"
        }
      ],
      "related": [],
      "schema_version": "1.7.0",
      "summary": "nss vulnerabilities",
      "upstream": [
        "UBUNTU-CVE-2022-3479",
        "UBUNTU-CVE-2023-0767"
      ]
    }