SB2017060216 - Debian update for nss
Published: June 2, 2017
Security Bulletin ID
SB2017060216
Severity
Low
Patch available
YES
Number of vulnerabilities
3
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Out-of-bounds write (CVE-ID: CVE-2017-5461)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to boundary error during Base64 decoding operation in the Network Security Services (NSS) library. A remote attacker can trigger out-of-bounds write and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
2) Information disclosure (CVE-ID: CVE-2017-5462)
A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS library has been updated to fix this issue to address this issue and Firefox has been updated with corresponding version of NSS.3) NULL pointer dereference (CVE-ID: CVE-2017-7502)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.The vulnerability exists due to NULL pointer dereference error in NSS since 3.24.0 when processing empty SSLv2 messages, received from clients. A remote attacker can send specially crafted request to vulnerable service and perform denial of service attack.
Remediation
Install update from vendor's website.