Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-5461

Опубликовано: 11 мая 2017
Источник: debian
EPSS Низкий

Описание

Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed52.0.1-1package
firefox-esrfixed45.9.0esr-1package
nssfixed2:3.30.1-1experimentalpackage
nssfixed2:3.26.2-1.1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2017-10/#CVE-2017-5461

  • https://www.mozilla.org/en-US/security/advisories/mfsa2017-11/#CVE-2017-5461

  • https://bugzilla.mozilla.org/show_bug.cgi?id=1344380

  • https://hg.mozilla.org/projects/nss/rev/77a5bb81dbaa

EPSS

Процентиль: 79%
0.01237
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.

CVSS3: 9.8
redhat
больше 8 лет назад

Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.

CVSS3: 9.8
nvd
больше 8 лет назад

Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.

CVSS3: 9.8
github
больше 3 лет назад

Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.

oracle-oval
больше 8 лет назад

ELSA-2017-1101: nss security update (CRITICAL)

EPSS

Процентиль: 79%
0.01237
Низкий