"Network Security Services (NSS) is a set of libraries designed to support cross-platform development of security-enabled client and server applications. "
Improper handling of memory allocation can cause NSS to leak out memory causing a DoS condition.
Vulnerable Systems:
* NSS version 3.10.2.0
* NSS version 3.9.3.0
Reportedly the Network Security Services (NSS) library will leak 256 bytes of memory per RSA cryptographic operation. After a certain amount of time, this causes the system to run out of memory and may lead to a system hang or panic state.
Disclosure Timeline:
23-Jun-2006 - Vulnerability researched
26-Jun-2006 - Detailed research
26-Jun-2006 - Vendor and Netscape developers was contacted
26-Jun-2006 - Security companies and several CERT units contacted