Bug 21878 - nss security vulnerability: CVE-2017-7805
Summary: nss security vulnerability: CVE-2017-7805
Status: RESOLVED DUPLICATE of bug 21785
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Mageia Bug Squad
QA Contact: Sec team
URL: https://www.debian.org/security/2017/...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-10-16 09:38 CEST by Zombie Ryushu
Modified: 2017-10-16 11:52 CEST (History)
0 users

See Also:
Source RPM: nss
CVE: CVE-2017-7805
Status comment:


Attachments

Description Zombie Ryushu 2017-10-16 09:38:38 CEST
Martin Thomson discovered that nss, the Mozilla Network Security Service library, is prone to a use-after-free vulnerability in the TLS 1.2 implementation when handshake hashes are generated. A remote attacker can take advantage of this flaw to cause an application using the nss library to crash, resulting in a denial of service, or potentially to execute arbitrary code.
Zombie Ryushu 2017-10-16 09:38:57 CEST

CVE: (none) => CVE-2017-7805

Comment 1 David Walser 2017-10-16 11:52:12 CEST
https://advisories.mageia.org/CVE-2017-7805.html

*** This bug has been marked as a duplicate of bug 21785 ***

Resolution: (none) => DUPLICATE
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.