CVE-2017-11697
Published: 27 December 2017
The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS) allows context-dependent attackers to cause a denial of service (floating point exception and crash) via a crafted cert8.db file.
Priority
CVSS 3 base score: 7.8
Status
Package | Release | Status |
---|---|---|
nss Launchpad, Ubuntu, Debian |
Upstream |
Needs triage
|
Ubuntu 20.10 (Groovy Gorilla) |
Not vulnerable
(2:3.49.1-1ubuntu1)
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Not vulnerable
(2:3.49.1-1ubuntu1)
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Deferred
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Deferred
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Deferred
|
Notes
Author | Note |
---|---|
mdeslaur | Upstream NSS will not be fixing this issue. this is an issue in libnssdbm. NSS 3.35 made SQLite the default datastore. NSS 3.49 stopped building the legacy datastore. |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11697
- http://seclists.org/fulldisclosure/2017/Aug/17
- NVD
- Launchpad
- Debian