Heap Overflow Vulnerability in NSS Affects Multiple Applications
CVE-2021-43527
What is CVE-2021-43527?
NSS versions earlier than 3.73 and 3.68.1 ESR are susceptible to a heap overflow vulnerability when processing DER-encoded DSA or RSA-PSS signatures. This could potentially affect applications utilizing NSS for signature verification in formats such as CMS, S/MIME, PKCS #7, or PKCS #12. Notably, email clients like Thunderbird and LibreOffice, along with PDF viewers such as Evince and Evolution, may be impacted. Applications employing NSS for certificate validation or TLS operations can also be vulnerable, contingent upon their specific configurations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
NSS < 3.73
NSS < 3.68.1
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved