Bug 1471171 (CVE-2017-7805)

Summary: CVE-2017-7805 nss: Potential use-after-free in TLS 1.2 server when verifying client authentication
Product: [Other] Security Response Reporter: Adam Mariš <amaris>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: amaris, breakin7, cperry, dueno, elio.maldonado.batiz, grocha, hkario, jrusnack, kdudka, kengert, meissner, nss-nspr-maint, rrelyea, security-response-team, szidek, yozone
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A use-after-free flaw was found in the TLS 1.2 implementation in the NSS library when client authentication was used. A malicious client could use this flaw to cause an application compiled against NSS to crash or, potentially, execute arbitrary code with the permission of the user running the application.
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-09-29 02:18:17 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1473508, 1473509, 1473510, 1473511, 1496926    
Bug Blocks: 1471174    

Description Adam Mariš 2017-07-14 15:05:22 UTC
Potential use-after-free vulnerability in nss in TLS 1.2 server when verifying client authentication was found.

Upstream bug:

https://bugzilla.mozilla.org/show_bug.cgi?id=1377618

Comment 10 Doran Moppert 2017-09-28 04:25:39 UTC
Acknowledgments:

Name: the Mozilla project
Upstream: Martin Thomson

Comment 13 Tomas Hoger 2017-09-28 19:00:22 UTC
Created nss tracking bugs for this issue:

Affects: fedora-all [bug 1496926]

Comment 14 errata-xmlrpc 2017-09-28 23:58:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6
  Red Hat Enterprise Linux 7

Via RHSA-2017:2832 https://access.redhat.com/errata/RHSA-2017:2832