Vulnerability CVE-2017-5462


Published: 2018-06-11

Description:
A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS library has been updated to fix this issue to address this issue and Firefox ESR 52.1 has been updated with NSS version 3.28.4. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

Type:

CWE-682

(Incorrect Calculation)

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Mozilla -> Firefox 
Mozilla -> Firefox esr 
Mozilla -> Network security services 
Mozilla -> Thunderbird 
Debian -> Debian linux 

 References:
http://www.securityfocus.com/bid/97940
http://www.securitytracker.com/id/1038320
https://bugzilla.mozilla.org/show_bug.cgi?id=1345089
https://security.gentoo.org/glsa/201705-04
https://www.debian.org/security/2017/dsa-3831
https://www.debian.org/security/2017/dsa-3872
https://www.mozilla.org/security/advisories/mfsa2017-10/
https://www.mozilla.org/security/advisories/mfsa2017-11/
https://www.mozilla.org/security/advisories/mfsa2017-12/
https://www.mozilla.org/security/advisories/mfsa2017-13/

Copyright 2024, cxsecurity.com

 

Back to Top