REDHAT-BUG-1440080: Mozilla nss esr vulnerability
An out-of-bounds write during Base64 decoding operation in the Network Security Services (NSS) library due to insufficient memory being allocated to the buffer. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-10/#CVE-2017-5461
Acknowledgements:
Name: the Mozilla project Upstream: Ronald Crane
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1440080?
The severity of REDHAT-BUG-1440080 is considered high due to the potential for exploitation leading to crashes.
How do I fix REDHAT-BUG-1440080?
To fix REDHAT-BUG-1440080, update to the latest version of Mozilla Network Security Services (NSS) that addresses this vulnerability.
What types of vulnerabilities does REDHAT-BUG-1440080 involve?
REDHAT-BUG-1440080 involves an out-of-bounds write vulnerability during Base64 decoding operations.
What impacts can REDHAT-BUG-1440080 have on my system?
The impact of REDHAT-BUG-1440080 can include application crashes and potential exploitation of the affected NSS library.
Is my software affected by REDHAT-BUG-1440080?
If you are using a version of the Mozilla Network Security Services library that is prior to the fixed releases, your software may be affected by REDHAT-BUG-1440080.