Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-5461

Опубликовано: 19 апр. 2017
Источник: redhat
CVSS3: 9.8

Описание

Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.

An out-of-bounds write flaw was found in the way NSS performed certain Base64-decoding operations. An attacker could use this flaw to create a specially crafted certificate which, when parsed by NSS, could cause it to crash or execute arbitrary code, using the permissions of the user running an application compiled against the NSS library.

Отчет

The security flaw exists in NSS library Base64 encoder/decoder code. Any application which uses NSS library to parse base64 encoded data could possibly be affected by the flaw. For example:

  1. Servers compiled against NSS which parse untrusted certificates or any other base64 encoded data from its users.
  2. Utilities like curl etc which use NSS to parse user provided base64 encoded certificates.
  3. Applications like Firefox which use NSS to parse client-certificates before passing them to the web server.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4nssAffected
Red Hat Enterprise Linux 5.9 Long LifenssFixedRHSA-2017:110320.04.2017
Red Hat Enterprise Linux 5 Extended Lifecycle SupportnssFixedRHSA-2017:110120.04.2017
Red Hat Enterprise Linux 6nssFixedRHSA-2017:110020.04.2017
Red Hat Enterprise Linux 6nss-utilFixedRHSA-2017:110020.04.2017
Red Hat Enterprise Linux 6.2 Advanced Update Supportnss-utilFixedRHSA-2017:110220.04.2017
Red Hat Enterprise Linux 6.4 Advanced Update Supportnss-utilFixedRHSA-2017:110220.04.2017
Red Hat Enterprise Linux 6.5 Advanced Update Supportnss-utilFixedRHSA-2017:110220.04.2017
Red Hat Enterprise Linux 6.5 Telco Extended Update Supportnss-utilFixedRHSA-2017:110220.04.2017
Red Hat Enterprise Linux 6.6 Advanced Update Supportnss-utilFixedRHSA-2017:110220.04.2017

Показывать по

Дополнительная информация

Статус:

Critical
https://bugzilla.redhat.com/show_bug.cgi?id=1440080nss: Write beyond bounds caused by bugs in Base64 de/encoding in nssb64d.c and nssb64e.c (MFSA 2017-10)

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.

CVSS3: 9.8
nvd
больше 8 лет назад

Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.

CVSS3: 9.8
debian
больше 8 лет назад

Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through ...

CVSS3: 9.8
github
больше 3 лет назад

Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.

oracle-oval
больше 8 лет назад

ELSA-2017-1101: nss security update (CRITICAL)

9.8 Critical

CVSS3

Уязвимость CVE-2017-5461