{"id":102446,"date":"2021-12-02T21:36:39","date_gmt":"2021-12-02T19:36:39","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-mozilla-nss-pozvolyayushhaya-vypolnit-kod-pri-obrabotke-sertifikatov"},"modified":"2021-12-02T21:36:39","modified_gmt":"2021-12-02T19:36:39","slug":"uyazvimost-v-mozilla-nss-pozvolyayushhaya-vypolnit-kod-pri-obrabotke-sertifikatov","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-mozilla-nss-pozvolyayushhaya-vypolnit-kod-pri-obrabotke-sertifikatov","title":{"rendered":"Nj\u00eb vulnerabilitet n\u00eb Mozilla NSS q\u00eb lejon ekzekutimin e kodit gjat\u00eb p\u00ebrpunimit t\u00eb certifikatave","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>N\u00eb paket\u00ebn e bibliotekave kriptografike NSS (Sh\u00ebrbimet e Siguris\u00eb Dritare), t\u00eb zhvilluara nga kompania Mozilla, \u00ebsht\u00eb zbuluar nj\u00eb vulnerabilitet kritik (CVE-2021-43527), i cili mund t\u00eb \u00e7oj\u00eb n\u00eb ekzekutimin e kodit nga agresori gjat\u00eb p\u00ebrpunimit t\u00eb n\u00ebnshkrimeve digjitale DSA ose RSA-PSS, t\u00eb caktuara me metod\u00ebn e kodimit DER (Rregullat e Kodimit t\u00eb Distinguar). Problemi, i cili ka marr\u00eb emrin kodor BigSig, \u00ebsht\u00eb zgjidhur n\u00eb versionet NSS 3.73 dhe NSS ESR 3.68.1. P\u00ebrdit\u00ebsimet e paketave jan\u00eb n\u00eb dispozicion p\u00ebr distribucione si Debian, RHEL, Ubuntu, SUSE, Arch Linux, Gentoo, FreeBSD. P\u00ebr momentin nuk ka p\u00ebrdit\u00ebsime p\u00ebr Fedora.    <\/p>\n<p> Problemi shfaqet n\u00eb aplikacionet q\u00eb p\u00ebrdorin NSS p\u00ebr p\u00ebrpunimin e n\u00ebnshkrimeve digjitale CMS, S\/MIME, PKCS #7 dhe PKCS #12, ose gjat\u00eb verifikimit t\u00eb certifikatave n\u00eb implementime TLS, X.509, OCSP dhe CRL. Vulnerabiliteti mund t\u00eb shfaqet n\u00eb aplikacione t\u00eb ndryshme klient\/serwer me mb\u00ebshtetje TLS, DTLS dhe S\/MIME, si klient\u00ebt e post\u00ebs elektronike dhe shikuesit PDF q\u00eb p\u00ebrdorin thirrjen NSS CERT_VerifyCertificate() p\u00ebr t\u00eb verifikuar n\u00ebnshkrimet digjitale.     <\/p>\n<p>Si shembuj t\u00eb aplikacioneve vulnerab\u00ebl p\u00ebrmendet LibreOffice, Evolution dhe Evince. Problemi potencialisht mund t\u00eb prek\u00eb gjithashtu projekte t\u00eb tilla si Pidgin, Apache OpenOffice, Suricata, Curl, Chrony, Red Hat Directory Server, Red Hat Certificate System, mod_nss p\u00ebr serverin http Apache, Oracle Communications Messaging Server, Oracle Directory Server Enterprise Edition. Megjithat\u00eb, vulnerabiliteti nuk shfaqet n\u00eb Firefox, Thunderbird dhe Tor Browser, t\u00eb cilat p\u00ebr verifikimin p\u00ebrdorin nj\u00eb bibliotek\u00eb t\u00eb ve\u00e7ant\u00eb mozilla::pkix, e cila gjithashtu \u00ebsht\u00eb pjes\u00eb e NSS. Problemi nuk prek as shfletuesit e bazuar n\u00eb Chromium (n\u00ebse ato nuk jan\u00eb nd\u00ebrtuar posa\u00e7\u00ebrisht me NSS), t\u00eb cil\u00ebt p\u00ebrdor\u00ebn NSS deri n\u00eb vitin 2015, por m\u00eb pas u kaluan n\u00eb BoringSSL.    <\/p>\n<p>Vulnerabiliteti shkaktohet nga nj\u00eb gabim n\u00eb kodin e verifikimit t\u00eb certifikatave n\u00eb funksionin vfy_CreateContext nga skedari secvfy.c. Gabimi shfaqet si gjat\u00eb leximin nga klienti t\u00eb certifikatave nga serveri, ashtu edhe gjat\u00eb p\u00ebrpunimit <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/sq\/server\/dts-prohoster\/\"   title=\"\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"3028\">\u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c<\/a> t\u00eb certifikatave t\u00eb klient\u00ebve. N\u00eb procesin e verifikimit t\u00eb n\u00ebnshkrimit digjital, t\u00eb koduar me metod\u00ebn DER, NSS e dekodon n\u00ebnshkrimin n\u00eb nj\u00eb tampon me madh\u00ebsi fikse dhe ia d\u00ebrgon k\u00ebt\u00eb tampon modulit PKCS #11. Gjat\u00eb p\u00ebrpunimit t\u00eb m\u00ebtejsh\u00ebm, p\u00ebr n\u00ebnshkrimet DSA dhe RSA-PSS, nuk kontrollohet sakt\u00ebsisht madh\u00ebsia, duke \u00e7uar n\u00eb tejkalimin e tamponit t\u00eb ndar\u00eb p\u00ebr struktur\u00ebn VFYContextStr, n\u00ebse madh\u00ebsia e n\u00ebnshkrimit digjital tejkalon 16384 bit (p\u00ebr tamponin ndahen 2048 byte, por nuk kontrollohet se n\u00ebnshkrimi mund t\u00eb ket\u00eb nj\u00eb madh\u00ebsi m\u00eb t\u00eb madhe).    <\/p>\n<p>Kodi q\u00eb p\u00ebrmban vulnerabilitet \u00ebsht\u00eb ndjekur q\u00eb nga viti 2003, por nuk p\u00ebrb\u00ebnte nj\u00eb k\u00ebrc\u00ebnim deri n\u00eb rifaktorizimin e b\u00ebr\u00eb n\u00eb vitin 2012. N\u00eb vitin 2017, gjat\u00eb realizimit t\u00eb mb\u00ebshtetjes RSA-PSS, u b\u00eb e nj\u00ebjta gabim. P\u00ebr t\u00eb kryer nj\u00eb sulm, nuk k\u00ebrkohet prodhimi i r\u00ebnd\u00eb i \u00e7el\u00ebsave t\u00eb caktuar p\u00ebr t\u00eb marr\u00eb t\u00eb dh\u00ebnat e nevojshme, pasi mbushja ndodh n\u00eb faz\u00ebn para verifikimit t\u00eb n\u00ebnshkrimit digjital. Pjesa e dh\u00ebnave q\u00eb del jasht\u00eb kufijve shkruhet n\u00eb zon\u00ebn e memories q\u00eb p\u00ebrmban tregues p\u00ebr funksionet, duke e b\u00ebr\u00eb krijimin e eksploit\u00ebve t\u00eb funksionojn\u00eb m\u00eb t\u00eb leht\u00eb.    <\/p>\n<p>Vulnerabiliteti u identifikua nga k\u00ebrkuesit e Google Project Zero gjat\u00eb eksperimentimeve me metoda t\u00eb reja t\u00eb testimit fuzzing dhe \u00ebsht\u00eb nj\u00eb shembull i shk\u00eblqyer se si vulnerabilitetet triviale mund t\u00eb mbeten t\u00eb paqena p\u00ebr nj\u00eb koh\u00eb t\u00eb gjat\u00eb n\u00eb nj\u00eb projekt t\u00eb njohur dhe t\u00eb testuar gjer\u00ebsisht:  <\/p>\n<ul>\n<li class=\"l\"> Kodi NSS mb\u00ebshtetet nga nj\u00eb ekip profesionist\u00ebsh q\u00eb merren me sigurin\u00eb, duke aplikuar metoda moderne t\u00eb testimit dhe analiz\u00ebs s\u00eb gabimeve. Ka disa programe p\u00ebr shp\u00ebrblime t\u00eb konsiderueshme p\u00ebr identifikimin e vulnerabiliteteve n\u00eb NSS.\n<li class=\"l\">  NSS ishte nj\u00eb nga projektet e para q\u00eb iu bashkua iniciativ\u00ebs Google oss-fuzz dhe gjithashtu u testua n\u00eb sistemin e fuzzing-t\u00eb zhvilluar nga Mozilla, duke p\u00ebrdorur libFuzzer.\n<li class=\"l\"> Kodi i bibliotek\u00ebs \u00ebsht\u00eb verifikuar shum\u00eb her\u00eb n\u00eb analizator\u00ebt e ndrysh\u00ebm statik\u00eb, duke p\u00ebrfshir\u00eb sh\u00ebrbimin Coverity q\u00eb i ka ndjekur q\u00eb nga viti 2008.\n<li class=\"l\"> Derisa n\u00eb vitin 2015, NSS u p\u00ebrdor n\u00eb Google Chrome dhe u testua n\u00eb m\u00ebnyr\u00eb t\u00eb pavarur nga Mozilla nga ekipi i Google (q\u00eb nga viti 2015, Chrome kaloi n\u00eb BoringSSL, por mb\u00ebshtetje p\u00ebr portin e bazuar n\u00eb NSS vazhdon).    <\/ul>\n<p>Problemet kryesore q\u00eb e b\u00ebn\u00eb k\u00ebt\u00eb \u00e7\u00ebshtje t\u00eb mbetet p\u00ebr nj\u00eb koh\u00eb t\u00eb gjat\u00eb t\u00eb paqen\u00eb:  <\/p>\n<ul>\n<li class=\"l\"> NSS \u043c\u043e\u0434\u0443\u043b\u044c\u043d\u0430\u044f \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430 \u0438 fuzzing-\u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u043f\u0440\u043e\u0432\u043e\u0434\u0438\u043b\u043e\u0441\u044c \u043d\u0435 \u0432 \u0446\u0435\u043b\u043e\u043c, \u0430 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0445 \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442\u043e\u0432. \u041d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u043e \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u043b\u0441\u044f \u043a\u043e\u0434 \u0434\u0435\u043a\u043e\u0434\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f DER \u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432 &#8212; \u0432 \u0445\u043e\u0434\u0435 fuzzing-\u0430 \u0432\u043f\u043e\u043b\u043d\u0435 \u043c\u043e\u0433 \u0431\u044b\u0442\u044c \u043f\u043e\u043b\u0443\u0447\u0435\u043d \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442, \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0438\u0439 \u043a \u043f\u0440\u043e\u044f\u0432\u043b\u0435\u043d\u0438\u044e \u0440\u0430\u0441\u0441\u043c\u0430\u0442\u0440\u0438\u0432\u0430\u0435\u043c\u043e\u0439 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043d\u043e \u0435\u0433\u043e \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u043d\u0435 \u0434\u043e\u0445\u043e\u0434\u0438\u043b\u0430 \u0434\u043e \u043a\u043e\u0434\u0430 \u0432\u0435\u0440\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0438 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043d\u0435 \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u0432\u0430\u043b\u0430 \u0441\u0435\u0431\u044f.\n<li class=\"l\"> Gjat\u00eb testimit fuzzing, u vendos\u00ebn kufij t\u00eb rrept\u00eb mbi madh\u00ebsin\u00eb e output-it (10000 byte) nd\u00ebrsa nuk kishte kufij t\u00eb till\u00eb n\u00eb NSS (shum\u00eb struktura mund t\u00eb kishin nj\u00eb madh\u00ebsi m\u00eb t\u00eb madhe se 10000 byte n\u00eb funksionimin normal, prandaj k\u00ebrkohej nj\u00eb volum m\u00eb i madh t\u00eb t\u00eb dh\u00ebnave hyr\u00ebse p\u00ebr t\u00eb identifikuar problemet). P\u00ebr nj\u00eb verifikim t\u00eb plot\u00eb, kufiri duhet t\u00eb ishte 224-1 byte (16 MB), q\u00eb korrespondon me madh\u00ebsin\u00eb maksimale t\u00eb certifikat\u00ebs q\u00eb lejohet n\u00eb TLS.\n<li class=\"l\"> E p\u00ebrfaq\u00ebsuar gabim rreth mbulimit t\u00eb kodit n\u00eb testimin fuzzing. Kodi i rreziksh\u00ebm u testua aktivisht, por me p\u00ebrdorimin e fuzzer-ave q\u00eb nuk ishin n\u00eb gjendje t\u00eb gjeneronin t\u00eb dh\u00ebnat hyr\u00ebse t\u00eb nevojshme. P\u00ebr shembull, fuzzer tls_server_target p\u00ebrdori nj\u00eb grup t\u00eb paracaktuar t\u00eb certifikatave, gj\u00eb q\u00eb kufizoi kontrollin e kodit t\u00eb verifikimit t\u00eb certifikat\u00ebs vet\u00ebm n\u00eb mesazhet TLS dhe ndryshimet e gjendjes s\u00eb protokollit.    <\/ul>\n<p>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=56268\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043d\u0430\u0431\u043e\u0440\u0435 \u043a\u0440\u0438\u043f\u0442\u043e\u0433\u0440\u0430\u0444\u0438\u0447\u0435\u0441\u043a\u0438\u0445 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a NSS (Network Security Services), \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Mozilla, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-43527), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0430 \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0446\u0438\u0444\u0440\u043e\u0432\u044b\u0445 \u043f\u043e\u0434\u043f\u0438\u0441\u0435\u0439 DSA \u0438\u043b\u0438 RSA-PSS, \u0437\u0430\u0434\u0430\u043d\u043d\u044b\u0445 \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u043c\u0435\u0442\u043e\u0434\u0430 \u043a\u043e\u0434\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f DER (Distinguished Encoding Rules). \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430, \u043a\u043e\u0442\u043e\u0440\u043e\u0439 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d\u043e \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f BigSig, \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0432 \u0432\u044b\u043f\u0443\u0441\u043a\u0430\u0445 NSS 3.73 \u0438 NSS ESR 3.68.1. \u041e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u043f\u0430\u043a\u0435\u0442\u043e\u0432 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-102446","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043d\u0430\u0431\u043e\u0440\u0435 \u043a\u0440\u0438\u043f\u0442\u043e\u0433\u0440\u0430\u0444\u0438\u0447\u0435\u0441\u043a\u0438\u0445 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a NSS (Network Security Services), \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Mozilla, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-43527), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0430 \u043f\u0440\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-mozilla-nss-pozvolyayushhaya-vypolnit-kod-pri-obrabotke-sertifikatov\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Mozilla NSS, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043d\u0430\u0431\u043e\u0440\u0435 \u043a\u0440\u0438\u043f\u0442\u043e\u0433\u0440\u0430\u0444\u0438\u0447\u0435\u0441\u043a\u0438\u0445 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a NSS (Network Security Services), \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Mozilla, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-43527), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0430 \u043f\u0440\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-mozilla-nss-pozvolyayushhaya-vypolnit-kod-pri-obrabotke-sertifikatov\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-12-02T19:36:39+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-12-02T19:36:39+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilitet n\u00eb Mozilla NSS, q\u00eb lejon ekzekutimin e kodit gjat\u00eb p\u00ebrpunimit t\u00eb certifikatave | ProHoster","description":"N\u00eb grupin e bibliotekave kriptografike NSS (Sh\u00ebrbimet e Siguris\u00eb n\u00eb Internet), t\u00eb zhvilluara nga Mozilla, \u00ebsht\u00eb zbuluar nj\u00eb vulnerabilitet kritik (CVE-2021-43527), i cili mund t\u00eb \u00e7oj\u00eb n\u00eb ekzekutimin e kodit nga sulmuesi.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-mozilla-nss-pozvolyayushhaya-vypolnit-kod-pri-obrabotke-sertifikatov","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Mozilla NSS, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u043a\u0430\u0442\u043e\u0432 | ProHoster","og:description":"\u0412 \u043d\u0430\u0431\u043e\u0440\u0435 \u043a\u0440\u0438\u043f\u0442\u043e\u0433\u0440\u0430\u0444\u0438\u0447\u0435\u0441\u043a\u0438\u0445 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a NSS (Network Security Services), \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u0435\u043c\u044b\u0445 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0435\u0439 Mozilla, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0430\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-43527), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0430 \u043f\u0440\u0438.","og:url":"https:\/\/prohoster.info\/sq\/blog\/news\/uyazvimost-v-mozilla-nss-pozvolyayushhaya-vypolnit-kod-pri-obrabotke-sertifikatov","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-12-02T19:36:39+00:00","article:modified_time":"2021-12-02T19:36:39+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"102446","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-12-02 19:38:04","updated":"2026-02-09 21:46:42","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/102446","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=102446"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/102446\/revisions"}],"predecessor-version":[{"id":160309,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/102446\/revisions\/160309"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=102446"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=102446"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=102446"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}