#873259 nss: CVE-2017-11698: heap-buffer-overflow (write of size 2) in __get_page (lib/dbm/src/h_page.c:704)

Package:
src:nss
Source:
nss
Submitter:
Salvatore Bonaccorso
Date:
2019-12-05 17:21:19 UTC
Severity:
important
#873259#5
Date:
2017-08-25 20:53:11 UTC
From:
To:
Hi,

the following vulnerability was published for nss.

CVE-2017-11698[0]:
|heap-buffer-overflow (write of size 2) in __get_page
|(lib/dbm/src/h_page.c:704)

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-11698
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11698

Please adjust the affected versions in the BTS as needed.

#873259#10
Date:
2017-09-08 19:27:08 UTC
From:
To:
Hi

I have not been able to confirm this statement as I do not have access to
the bugzilla entries but Redhat advisory claims that in order to exploit
this you actually need to create crafted NDB DBM files which is very likely
to be a problem in practice. Typically you need write access for the user
running the service and then there are easier ways to cause problems than
this. This means that this is really a minor security problem if any. It
would however be good if someone could confirm the statement from Redhat.

I have marked the issue as no-dsa for wheezy but if someone have
information that proove redhat to be wrong then we should change that
statement.

Best regards

// Ola