Back

HIGH

nss: Heap-buffer-overflow in __hash_open

Published Dec 27, 2017

Description

Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.

Affected products

Remediation

Red Hat statement

NSS uses a local DBM database to store configuration and security (Certificates etc) information. These database files are created by NSS during startup and is used during its normal operation. These files are not read/retrieved from an external source. This flaw is related to specially-crafted NSS DBM files. So the only way to exploit this flaw is to replace the local NSS db with these files which require local user access on the machine running NSS. Therefore Red Hat Product Security does not consider this as a security flaw.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 27, 2017
Updated Aug 5, 2024
Reserved Jul 27, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Aug 9, 2017