Information disclosure in Firefox ESR and Mozilla Firefox - CVE-2017-5462
Published: April 19, 2017
Vulnerability identifier: #VU6339
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-5462
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS library has been updated to fix this issue to address this issue and Firefox has been updated with corresponding version of NSS.
Affected software
Firefox ESR
Mozilla Firefox
Debian Linux
Gentoo Linux
SUSE Linux
Ubuntu
nss (Alpine package)
Gentoo dev-libs/nss
Mozilla Thunderbird
Mozilla Firefox
Debian Linux
Gentoo Linux
SUSE Linux
Ubuntu
nss (Alpine package)
Gentoo dev-libs/nss
Mozilla Thunderbird
How to mitigate CVE-2017-5462
Update to Firefox 53, Firefox ESR 45.9 or Firefox ESR 52.1.
nss (Alpine package) - update to 3.23-r1
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Firefox
- Multiple vulnerabilities in Mozilla Thunderbird
- Gentoo update for Mozilla Network Security Service (NSS)
- Debian update for nss
- SUSE Linux update for MozillaFirefox
- Ubuntu update for Firefox
- Ubuntu update for Firefox
- Gentoo update for Mozilla Firefox
- SUSE Linux update for MozillaFirefox
- Information disclosure in nss (Alpine package)