CVE-2017-11696: Buffer Overflow
Heap-based buffer overflow in the hashopen function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.
Other sources
Mozilla Network Security Services (NSS), as used in Mozilla Firefox is vulnerable to a heap-based buffer overflow, caused by improper bounds checking by hashopen() in 'lib/dbm/src/hash.c. By using the NSS tool certutil and malformed cert8.db file, a local attacker could overflow a buffer and execute arbitrary code on the system with elevated privileges.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this heap-based buffer overflow?
The vulnerability ID for this heap-based buffer overflow is CVE-2017-11696.
What is the severity of CVE-2017-11696?
The severity of CVE-2017-11696 is high with a CVSS score of 7.8.
Which software is affected by CVE-2017-11696?
Mozilla Network Security Services (NSS) is affected by CVE-2017-11696.
How can context-dependent attackers exploit CVE-2017-11696?
Context-dependent attackers can exploit CVE-2017-11696 by using a crafted cert8.db file.
How can I fix CVE-2017-11696?
To fix CVE-2017-11696, it is recommended to update Mozilla Network Security Services to a patched version.