Vulnerability in Mozilla NSS allows code execution when processing certificates
A critical vulnerability (CVE-2021-43527) has been identified in the set of cryptographic libraries NSS (Network Security Services) developed by Mozilla, which could lead to arbitrary code execution when handling DSA or RSA-PSS digital signatures set using the DER (Distinguished Encoding Rules) encoding method. The issue, codenamed BigSig, has been fixed in NSS 3.73 and NSS ESR 3.68.1 releases. Package updates […]
