CVE-2017-5462
Summary
| CVE | CVE-2017-5462 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-11 21:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS library has been updated to fix this issue to address this issue and Firefox ESR 52.1 has been updated with NSS version 3.28.4. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Security vulnerabilities fixed in Thunderbird 52.1 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| Mozilla Firefox Multiple Bugs Let Remote Users Bypass Security Restrictions, Spoof URLs, Obtain Potentially Sensitive Information, Deny Service, and Execute Arbitrary Code - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| 1345089 - (CVE-2017-5462) DRBG addition is broken |
CONFIRM |
bugzilla.mozilla.org |
Issue Tracking |
| Security vulnerabilities fixed in Firefox 53 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| Mozilla Network Security Service (NSS): Multiple vulnerabilities (GLSA 201705-04) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| Mozilla Firefox Multiple Security Vulnerabilities |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Security vulnerabilities fixed in Firefox ESR 45.9 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| Debian -- Security Information -- DSA-3872-1 nss |
DEBIAN |
www.debian.org |
Third Party Advisory |
| Security vulnerabilities fixed in Firefox ESR 52.1 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| Debian -- Security Information -- DSA-3831-1 firefox-esr |
DEBIAN |
www.debian.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 690289 Free Berkeley Software Distribution (FreeBSD) Security Update for mozilla (5e0a038a-ca30-416d-a2f5-38cbf5e7df33)
- 710287 Gentoo Linux Mozilla Firefox Multiple Vulnerabilities (GLSA 201802-03)
- 710397 Gentoo Linux Mozilla Network Security Service (NSS) Multiple Vulnerabilities (GLSA 201705-04)