Do your applications use this vulnerable package?
Test your applications
Overview
The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS) allows context-dependent attackers to cause a denial of service (floating point exception and crash) via a crafted cert8.db file.
References
CVSS Score
7.8
low severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredLow
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- CVE
- CVE-2017-11697
- CWE
- CWE-119
- Snyk ID
- SNYK-DEBIAN10-NSS-421286
- Disclosed
- 27 Dec, 2017
- Published
- 27 Dec, 2017