CVE-2017-11695 PUBLISHED

Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.

EPSS 0.09% · 25.2th percentile

Risk Scores

EPSS Score
0.09%
25.2th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSnss2:3.35-2ubuntu2.16, 2:3.35-2ubuntu2.15, 2:3.35-2ubuntu2.14
Ubuntu:Pro:14.04:LTSnss2:3.19.2.1-0ubuntu0.14.04.1, 2:3.19.2.1-0ubuntu0.14.04.2, 0
Ubuntu:Pro:16.04:LTSnss2:3.28.4-0ubuntu0.16.04.12, 2:3.28.4-0ubuntu0.16.04.13, 2:3.28.4-0ubuntu0.16.04.14

Timeline

References

Open in Interactive Console →