nss Client Authentication Vulnerability in Mozilla Products
CVE-2022-3479

7.5HIGH

Key Information:

Vendor
Mozilla
Status
Vendor
CVE Published:
14 October 2022

Summary

A vulnerability in the nss client authentication process allows for a segmentation fault or application crash when there is no user certificate in the database. This issue can potentially disrupt operations depending on the nss for secure communications, leading to unexpected application behaviors.

Affected Version(s)

nss 3.81

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.