Bug 1487130 (CVE-2017-11698)

Summary: CVE-2017-11698 nss: Heap-buffer-overflow in __get_page
Product: [Other] Security Response Reporter: Andrej Nemec <anemec>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: dueno, elio.maldonado.batiz, kdudka, kengert, nss-nspr-maint, rrelyea, sardella
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-09-08 04:40:32 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On:    
Bug Blocks: 1487134    

Description Andrej Nemec 2017-08-31 09:54:25 UTC
A heap-buffer-overflow (write of size 2) in __get_page (lib/dbm/src/h_page.c:704) was found in nss.

Upstream bug:


Comment 1 Andrej Nemec 2017-08-31 09:57:59 UTC


Comment 2 Huzaifa S. Sidhpurwala 2017-09-08 04:40:41 UTC

NSS uses a local DBM database to store configuration and security (Certificates etc) information. These database files are created by NSS during startup and is used during its normal operation. These files are not read/retrieved from an external source. This flaw is related to specially-crafted NSS DBM files. So the only way to exploit this flaw is to replace the local NSS db with these files which require local user access on the machine running NSS. Therefore Red Hat Product Security does not consider this as a security flaw.