SB2017050701 - Gentoo update for Mozilla Network Security Service (NSS) 



SB2017050701 - Gentoo update for Mozilla Network Security Service (NSS)

Published: May 7, 2017 Updated: May 8, 2017

Security Bulletin ID SB2017050701
Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Out-of-bounds write (CVE-ID: CVE-2017-5461)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to boundary error during Base64 decoding operation in the Network Security Services (NSS) library. A remote attacker can trigger out-of-bounds write and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


2) Information disclosure (CVE-ID: CVE-2017-5462)

A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS library has been updated to fix this issue to address this issue and Firefox has been updated with corresponding version of NSS.

Remediation

Install update from vendor's website.