CVE-2017-5462

A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS library has been updated to fix this issue to address this issue and Firefox ESR 52.1 has been updated with NSS version 3.28.4. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Configurations

Configuration 1 (hide)

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:52.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:network_security_services:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:27

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/97940 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/97940 - Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1038320 - Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1038320 - Third Party Advisory, VDB Entry
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1345089 - Issue Tracking () https://bugzilla.mozilla.org/show_bug.cgi?id=1345089 - Issue Tracking
References () https://security.gentoo.org/glsa/201705-04 - Third Party Advisory () https://security.gentoo.org/glsa/201705-04 - Third Party Advisory
References () https://www.debian.org/security/2017/dsa-3831 - Third Party Advisory () https://www.debian.org/security/2017/dsa-3831 - Third Party Advisory
References () https://www.debian.org/security/2017/dsa-3872 - Third Party Advisory () https://www.debian.org/security/2017/dsa-3872 - Third Party Advisory
References () https://www.mozilla.org/security/advisories/mfsa2017-10/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2017-10/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2017-11/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2017-11/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2017-12/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2017-12/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2017-13/ - Vendor Advisory () https://www.mozilla.org/security/advisories/mfsa2017-13/ - Vendor Advisory

21 Oct 2024, 13:55

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox_esr:52.0:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:52.0:*:*:*:*:*:*:*

Information

Published : 2018-06-11 21:29

Updated : 2024-11-21 03:27


NVD link : CVE-2017-5462

Mitre link : CVE-2017-5462

CVE.ORG link : CVE-2017-5462


JSON object : View

Products Affected

debian

  • debian_linux

mozilla

  • network_security_services
  • thunderbird
  • firefox_esr
  • firefox
CWE
CWE-682

Incorrect Calculation