CVE-2017-11695: Buffer Overflow
Heap-based buffer overflow in the allocsegs function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.
Other sources
Mozilla Network Security Services (NSS), as used in Mozilla Firefox is vulnerable to a heap-based buffer overflow, caused by improper bounds checking by allocsegs() in 'lib/dbm/src/hash.c. By using the NSS tool certutil and malformed cert8.db file, a local attacker could overflow a buffer and execute arbitrary code on the system with elevated privileges.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-11695?
CVE-2017-11695 is a vulnerability that allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.
How severe is CVE-2017-11695?
CVE-2017-11695 has a severity score of 7.8 (High).
Which software is affected by CVE-2017-11695?
Mozilla Network Security Services is affected by CVE-2017-11695.
How can the heap-based buffer overflow in CVE-2017-11695 be exploited?
The heap-based buffer overflow in CVE-2017-11695 can be exploited by using a crafted cert8.db file.
Are there any references available for CVE-2017-11695?
Yes, you can find references for CVE-2017-11695 at the following links: [Link1](http://packetstormsecurity.com/files/143735/NSS-Buffer-Overflows-Floating-Point-Exception.html), [Link2](http://seclists.org/fulldisclosure/2017/Aug/17), [Link3](http://www.geeknik.net/9brdqk6xu)