CVE-2017-5461

critical
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.

References

https://www.mozilla.org/en-US/security/advisories/mfsa2017-13/#CVE-2017-5461

https://www.mozilla.org/en-US/security/advisories/mfsa2017-12/#CVE-2017-5461

https://www.mozilla.org/en-US/security/advisories/mfsa2017-11/#CVE-2017-5461

https://www.mozilla.org/en-US/security/advisories/mfsa2017-10/#CVE-2017-5461

https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.30.1_release_notes

https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.29.5_release_notes

https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.28.4_release_notes

https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.21.4_release_notes

https://bugzilla.mozilla.org/show_bug.cgi?id=1344380

http://www.securityfocus.com/bid/98050

https://security.gentoo.org/glsa/201705-04

http://www.securitytracker.com/id/1038320

http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html

http://www.debian.org/security/2017/dsa-3872

http://www.debian.org/security/2017/dsa-3831

https://access.redhat.com/errata/RHSA-2017:1103

https://access.redhat.com/errata/RHSA-2017:1102

https://access.redhat.com/errata/RHSA-2017:1101

https://access.redhat.com/errata/RHSA-2017:1100

http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html

Details

Source: MITRE

Published: 2017-05-11

Updated: 2021-07-20

Type: CWE-787

Risk Information

CVSS v2

Base Score: 7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 10

Severity: HIGH

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 3.9

Severity: CRITICAL

Tenable Plugins

View all (43 total)

IDNameProductFamilySeverity
127337NewStart CGSL MAIN 4.05 : nss Multiple Vulnerabilities (NS-SA-2019-0105)NessusNewStart CGSL Local Security Checks
critical
112175RHEL 5 : nss (RHSA-2017:1101)NessusRed Hat Local Security Checks
critical
106884GLSA-201802-03 : Mozilla Firefox: Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
106299Oracle Fusion Middleware Oracle HTTP Server Multiple Vulnerabilities (January 2018 CPU)NessusWeb Servers
critical
102694SUSE SLES11 Security Update : MozillaFirefox, MozillaFirefox-branding-SLED, firefox-gcc5, mozilla-nss (SUSE-SU-2017:2235-1)NessusSuSE Local Security Checks
critical
101454Virtuozzo 6 : nss-util / nss-util-devel (VZLSA-2017-1100)NessusVirtuozzo Local Security Checks
critical
101055SUSE SLED12 / SLES12 Security Update : MozillaFirefox, MozillaFirefox-branding-SLE (SUSE-SU-2017:1669-1)NessusSuSE Local Security Checks
critical
100580Debian DSA-3872-1 : nss - security updateNessusDebian Local Security Checks
critical
100302Debian DLA-946-1 : nss security updateNessusDebian Local Security Checks
critical
100249Ubuntu 14.04 LTS / 16.04 LTS / 16.10 / 17.04 : thunderbird vulnerabilities (USN-3278-1)NessusUbuntu Local Security Checks
critical
100153Ubuntu 14.04 LTS / 16.04 LTS / 16.10 / 17.04 : firefox regression (USN-3260-2)NessusUbuntu Local Security Checks
critical
100151SUSE SLED12 / SLES12 Security Update : MozillaFirefox, mozilla-nss, mozilla-nspr, java-1_8_0-openjdk (SUSE-SU-2017:1248-1)NessusSuSE Local Security Checks
critical
100020openSUSE Security Update : MozillaThunderbird (openSUSE-2017-545)NessusSuSE Local Security Checks
critical
100018GLSA-201705-04 : Mozilla Network Security Service (NSS): Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
99992SUSE SLES11 Security Update : MozillaFirefox, mozilla-nss, mozilla-nspr (SUSE-SU-2017:1175-1)NessusSuSE Local Security Checks
critical
99968Mozilla Thunderbird < 52.1 Multiple VulnerabilitiesNessusWindows
critical
99967Mozilla Thunderbird < 52.1 Multiple Vulnerabilities (macOS)NessusMacOS X Local Security Checks
critical
99942EulerOS 2.0 SP2 : nss, nss-util (EulerOS-SA-2017-1076)NessusHuawei Local Security Checks
critical
99941EulerOS 2.0 SP1 : nss, nss-util (EulerOS-SA-2017-1075)NessusHuawei Local Security Checks
critical
99755Oracle Linux 5 : nss (ELSA-2017-1101)NessusOracle Linux Local Security Checks
critical
99724Ubuntu 14.04 LTS / 16.04 LTS / 16.10 / 17.04 : nss vulnerabilities (USN-3270-1)NessusUbuntu Local Security Checks
critical
99713Amazon Linux AMI : nss / nss-util (ALAS-2017-825)NessusAmazon Linux Local Security Checks
critical
99649openSUSE Security Update : Mozilla Firefox (openSUSE-2017-509)NessusSuSE Local Security Checks
critical
99632Mozilla Firefox < 53 Multiple VulnerabilitiesNessusWindows
critical
99631Mozilla Firefox ESR 52.x < 52.1 Multiple VulnerabilitiesNessusWindows
critical
99630Mozilla Firefox ESR 45.x < 45.9 Multiple VulnerabilitiesNessusWindows
critical
99629Mozilla Firefox < 53 Multiple Vulnerabilities (macOS)NessusMacOS X Local Security Checks
critical
99628Mozilla Firefox ESR < 52.1 Multiple Vulnerabilities (macOS)NessusMacOS X Local Security Checks
critical
99627Mozilla Firefox ESR 45.x < 45.9 Multiple Vulnerabilities (macOS)NessusMacOS X Local Security Checks
critical
99626Ubuntu 14.04 LTS / 16.04 LTS / 16.10 / 17.04 : firefox vulnerabilities (USN-3260-1)NessusUbuntu Local Security Checks
critical
99620Scientific Linux Security Update : nss-util on SL6.x, SL7.x x86_64 (20170420)NessusScientific Linux Local Security Checks
critical
99600Debian DLA-906-1 : firefox-esr security updateNessusDebian Local Security Checks
critical
99577Scientific Linux Security Update : nss and nss-util on SL6.x, SL7.x i386/x86_64 (20170420)NessusScientific Linux Local Security Checks
critical
99562Oracle Linux 6 / 7 : nss / nss-util (ELSA-2017-1100)NessusOracle Linux Local Security Checks
critical
99553FreeBSD : NSS -- multiple vulnerabilities (4cb165f0-6e48-423e-8147-92255d35c0f7)NessusFreeBSD Local Security Checks
critical
99536CentOS 6 / 7 : nss / nss-util (CESA-2017:1100)NessusCentOS Local Security Checks
critical
700066Mozilla Firefox ESR < 52.1 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
700065Mozilla Firefox < 53 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
high
99504RHEL 5 : nss (RHSA-2017:1103)NessusRed Hat Local Security Checks
critical
99503RHEL 6 / 7 : nss-util (RHSA-2017:1102)NessusRed Hat Local Security Checks
critical
99502RHEL 6 / 7 : nss and nss-util (RHSA-2017:1100)NessusRed Hat Local Security Checks
critical
99496FreeBSD : mozilla -- multiple vulnerabilities (5e0a038a-ca30-416d-a2f5-38cbf5e7df33)NessusFreeBSD Local Security Checks
critical
99485Debian DSA-3831-1 : firefox-esr - security updateNessusDebian Local Security Checks
critical