CVE-2017-5461
CRITICALMozilla Network Security Services < 3.21.4 - Out-of-bounds Write via Base64 Operations
Title source: llmDescription
Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.
References (21)
Core 21
Core References
Third Party Advisory vendor-advisory
x_refsource_gentoo
https://security.gentoo.org/glsa/201705-04
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/98050
Patch vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1103
Patch vendor-advisory
x_refsource_debian
http://www.debian.org/security/2017/dsa-3831
Patch vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1100
Patch vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1102
Patch vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1101
Patch vendor-advisory
x_refsource_debian
http://www.debian.org/security/2017/dsa-3872
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1038320
Patch x_refsource_confirm
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
Patch x_refsource_confirm
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
Vendor Advisory x_refsource_misc
https://www.oracle.com//security-alerts/cpujul2021.html
Release Notes, Vendor Advisory x_refsource_confirm
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.21.4_release_notes
Release Notes, Vendor Advisory x_refsource_confirm
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.30.1_release_notes
Release Notes, Vendor Advisory x_refsource_confirm
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.29.5_release_notes
Release Notes, Vendor Advisory x_refsource_confirm
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.28.4_release_notes
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/en-US/security/advisories/mfsa2017-11/#CVE-2017-5461
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/en-US/security/advisories/mfsa2017-10/#CVE-2017-5461
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/en-US/security/advisories/mfsa2017-13/#CVE-2017-5461
Issue Tracking, Permissions Required x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=1344380
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/en-US/security/advisories/mfsa2017-12/#CVE-2017-5461
Scores
CVSS v3
9.8
EPSS
0.0061
EPSS Percentile
69.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-787
Status
published
Products (5)
Mozilla/Firefox
unspecified - 53
Mozilla/Firefox ESR
unspecified - 45.9
Mozilla/Firefox ESR
unspecified - 52.1
mozilla/network_security_services
< 3.21.4
Mozilla/Thunderbird
unspecified - 52.1
Published
May 11, 2017
Tracked Since
Feb 18, 2026