Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-5462


A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS library has been updated to fix this issue to address this issue and Firefox ESR 52.1 has been updated with NSS version 3.28.4. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.


Published

2018-06-11T21:29:07.093

Last Modified

2024-11-21T03:27:40.397

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 5.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-682

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System debian debian_linux 8.0 Yes
Application mozilla firefox < 53.0 Yes
Application mozilla firefox 52.0 Yes
Application mozilla firefox_esr < 45.9.0 Yes
Application mozilla network_security_services < 3.28.4 Yes
Application mozilla thunderbird < 52.1.0 Yes

References