Out-of-bounds write in Firefox ESR and Mozilla Firefox - CVE-2017-5461
Published: April 19, 2017
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to boundary error during Base64 decoding operation in the Network Security Services (NSS) library. A remote attacker can trigger out-of-bounds write and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
Mozilla Firefox
Amazon Linux AMI
Arch Linux
Debian Linux
Gentoo Linux
SUSE Linux
Ubuntu
Fedora
nss (Alpine package)
Gentoo dev-libs/nss
firefox
Mozilla Thunderbird
How to mitigate CVE-2017-5461
firefox - update to 53.0-2.fc24
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Firefox
- Multiple vulnerabilities in Mozilla Thunderbird
- Gentoo update for Mozilla Network Security Service (NSS)
- Arch Linux update for lib32-nss
- Debian update for nss
- SUSE Linux update for MozillaFirefox
- Arch Linux update for firefox
- Arch Linux update for nss
- Ubuntu update for NSS
- Ubuntu update for Firefox
- Ubuntu update for NSS
- Ubuntu update for Firefox
- Amazon Linux AMI update for nss, nss-util
- Gentoo update for Mozilla Firefox
- OpenSUSE Linux update for Mozilla Firefox
- SUSE Linux update for MozillaFirefox
- Out-of-bounds write in nss (Alpine package)
- Fedora 24 update for firefox