nss: Write beyond bounds caused by bugs in Base64 de/encoding in nssb64d.c and nssb64e.c (MFSA 2017-10)
Published May 11, 2017
9.8
CRITICALCVSS 3.0
EPSS 4.70%
Description
Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<53
- Version
-
- Version unspecifiedStatusaffectedConstraints<45.9
- Version unspecifiedStatusaffectedConstraints<52.1
- Version
-
- Version unspecifiedStatusaffectedConstraints<52.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Mozilla | Firefox | n/a |
| |||||||||
| Mozilla | Firefox ESR | n/a |
| |||||||||
| Mozilla | Thunderbird | n/a |
|
- < 3.21.4
- > 3.22 · < 3.28.4
- ≥ 3.29 · < 3.29.5
- ≥ 3.30 · < 3.30.1
No data.
Red Hat Enterprise Linux 5 Extended Lifecycle Support
nss-0:3.21.4-1.el5_11
Fixed · RHSA-2017:1101
Red Hat Enterprise Linux 5.9 Long Life
nss-0:3.14.3-11.el5_9
Fixed · RHSA-2017:1103
Red Hat Enterprise Linux 6
nss-0:3.28.4-1.el6_9
Fixed · RHSA-2017:1100
Red Hat Enterprise Linux 6
nss-util-0:3.28.4-1.el6_9
Fixed · RHSA-2017:1100
Red Hat Enterprise Linux 6.2 Advanced Update Support
nss-util-0:3.13.1-11.el6_2
Fixed · RHSA-2017:1102
Red Hat Enterprise Linux 6.4 Advanced Update Support
nss-util-0:3.14.3-9.el6_4
Fixed · RHSA-2017:1102
Red Hat Enterprise Linux 6.5 Advanced Update Support
nss-util-0:3.16.1-5.el6_5
Fixed · RHSA-2017:1102
Red Hat Enterprise Linux 6.5 Telco Extended Update Support
nss-util-0:3.16.1-5.el6_5
Fixed · RHSA-2017:1102
Red Hat Enterprise Linux 6.6 Advanced Update Support
nss-util-0:3.19.1-4.el6_6
Fixed · RHSA-2017:1102
Red Hat Enterprise Linux 6.6 Telco Extended Update Support
nss-util-0:3.19.1-4.el6_6
Fixed · RHSA-2017:1102
Red Hat Enterprise Linux 6.7 Extended Update Support
nss-util-0:3.21.4-1.el6_7
Fixed · RHSA-2017:1102
Red Hat Enterprise Linux 7
nss-0:3.28.4-1.0.el7_3
Fixed · RHSA-2017:1100
Red Hat Enterprise Linux 7
nss-util-0:3.28.4-1.0.el7_3
Fixed · RHSA-2017:1100
Red Hat Enterprise Linux 7.2 Extended Update Support
nss-util-0:3.21.4-1.el7_2
Fixed · RHSA-2017:1102
Red Hat Enterprise Linux 4
nss
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 Extended Lifecycle Support | nss-0:3.21.4-1.el5_11 | Fixed | RHSA-2017:1101 |
| Red Hat Enterprise Linux 5.9 Long Life | nss-0:3.14.3-11.el5_9 | Fixed | RHSA-2017:1103 |
| Red Hat Enterprise Linux 6 | nss-0:3.28.4-1.el6_9 | Fixed | RHSA-2017:1100 |
| Red Hat Enterprise Linux 6 | nss-util-0:3.28.4-1.el6_9 | Fixed | RHSA-2017:1100 |
| Red Hat Enterprise Linux 6.2 Advanced Update Support | nss-util-0:3.13.1-11.el6_2 | Fixed | RHSA-2017:1102 |
| Red Hat Enterprise Linux 6.4 Advanced Update Support | nss-util-0:3.14.3-9.el6_4 | Fixed | RHSA-2017:1102 |
| Red Hat Enterprise Linux 6.5 Advanced Update Support | nss-util-0:3.16.1-5.el6_5 | Fixed | RHSA-2017:1102 |
| Red Hat Enterprise Linux 6.5 Telco Extended Update Support | nss-util-0:3.16.1-5.el6_5 | Fixed | RHSA-2017:1102 |
| Red Hat Enterprise Linux 6.6 Advanced Update Support | nss-util-0:3.19.1-4.el6_6 | Fixed | RHSA-2017:1102 |
| Red Hat Enterprise Linux 6.6 Telco Extended Update Support | nss-util-0:3.19.1-4.el6_6 | Fixed | RHSA-2017:1102 |
| Red Hat Enterprise Linux 6.7 Extended Update Support | nss-util-0:3.21.4-1.el6_7 | Fixed | RHSA-2017:1102 |
| Red Hat Enterprise Linux 7 | nss-0:3.28.4-1.0.el7_3 | Fixed | RHSA-2017:1100 |
| Red Hat Enterprise Linux 7 | nss-util-0:3.28.4-1.0.el7_3 | Fixed | RHSA-2017:1100 |
| Red Hat Enterprise Linux 7.2 Extended Update Support | nss-util-0:3.21.4-1.el7_2 | Fixed | RHSA-2017:1102 |
| Red Hat Enterprise Linux 4 | nss | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The security flaw exists in NSS library Base64 encoder/decoder code. Any application which uses NSS library to parse base64 encoded data could possibly be affected by the flaw. For example: 1. Servers compiled against NSS which parse untrusted certificates or any other base64 encoded data from its users. 2. Utilities like curl etc which use NSS to parse user provided base64 encoded certificates. 3. Applications like Firefox which use NSS to parse client-certificates before passing them to the web server.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (19 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.70% (0.04703) | 91.53th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.74% (0.04741) | 90.68th | v5 (v2026.06.15) |
| Mar 30, 2025 | 1.41% (0.01411) | 78.74th | v4 (v2025.03.14) |
| Mar 29, 2025 | 4.51% (0.04511) | 81.53th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.41% (0.01411) | 79.19th | v4 (v2025.03.14) |
| Dec 17, 2024 | 2.97% (0.02975) | 90.64th | v3 (v2023.03.01) |
| Dec 12, 2024 | 5.40% (0.05403) | 93.43th | v3 (v2023.03.01) |
| May 23, 2024 | 4.50% (0.04495) | 92.47th | v3 (v2023.03.01) |
| Apr 13, 2024 | 3.17% (0.03173) | 91.01th | v3 (v2023.03.01) |
| Mar 1, 2024 | 2.99% (0.02986) | 90.60th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.33% (0.01326) | 83.90th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.36% (0.04358) | 88.02th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.36% (0.04358) | 86.83th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.36% (0.04358) | 70.59th | v2 (v2022.01.01) |
| Feb 3, 2022 | 6.83% (0.06834) | 83.29th | v1 |
| Jan 6, 2022 | 6.83% (0.06834) | 83.13th | v1 |
| Sep 1, 2021 | 6.83% (0.06834) | 91.09th | v1 |
| Jul 21, 2021 | 6.83% (0.06834) | 0.00th | v1 |
| Apr 14, 2021 | 6.54% (0.06542) | 0.00th | v1 |
References (25)
- http://www.debian.org/security/2017/dsa-3831 vendor-advisoryx_refsource_DEBIANPatch
- http://www.debian.org/security/2017/dsa-3872 vendor-advisoryx_refsource_DEBIANPatch
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html x_refsource_CONFIRMPatch
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html x_refsource_CONFIRMPatch
- http://www.securityfocus.com/bid/98050 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038320 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:1100 vendor-advisoryx_refsource_REDHATPatch
- https://access.redhat.com/errata/RHSA-2017:1101 vendor-advisoryx_refsource_REDHATPatch
- https://access.redhat.com/errata/RHSA-2017:1102 vendor-advisoryx_refsource_REDHATPatch
- https://access.redhat.com/errata/RHSA-2017:1103 vendor-advisoryx_refsource_REDHATPatch
- https://access.redhat.com/security/cve/CVE-2017-5461 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1344380 x_refsource_CONFIRMIssue TrackingPermissions Required
- https://bugzilla.redhat.com/show_bug.cgi?id=1440080 Issue Tracking
- https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.21.4_release_notes x_refsource_CONFIRMRelease NotesVendor Advisory
- https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.28.4_release_notes x_refsource_CONFIRMRelease NotesVendor Advisory
- https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.29.5_release_notes x_refsource_CONFIRMRelease NotesVendor Advisory
- https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.30.1_release_notes x_refsource_CONFIRMRelease NotesVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-5461
- https://security.gentoo.org/glsa/201705-04 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-5461
- https://www.mozilla.org/en-US/security/advisories/mfsa2017-10/#CVE-2017-5461 x_refsource_CONFIRMVendor Advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2017-11/#CVE-2017-5461 x_refsource_CONFIRMVendor Advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2017-12/#CVE-2017-5461 x_refsource_CONFIRMVendor Advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2017-13/#CVE-2017-5461 x_refsource_CONFIRMVendor Advisory
- https://www.oracle.com//security-alerts/cpujul2021.html x_refsource_MISC
Change history (0)
No recorded changes yet.