Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1471171 - (CVE-2017-7805) CVE-2017-7805 nss: Potential use-after-free in TLS 1.2 server when verifying client authentication
CVE-2017-7805 nss: Potential use-after-free in TLS 1.2 server when verifying ...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20170928,repo...
: Security
Depends On: 1473508 1473509 1473510 1473511 1496926
Blocks: 1471174
  Show dependency treegraph
 
Reported: 2017-07-14 11:05 EDT by Adam Mariš
Modified: 2018-07-23 09:09 EDT (History)
16 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A use-after-free flaw was found in the TLS 1.2 implementation in the NSS library when client authentication was used. A malicious client could use this flaw to cause an application compiled against NSS to crash or, potentially, execute arbitrary code with the permission of the user running the application.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2017-09-28 22:18:17 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2017:2832 normal SHIPPED_LIVE Important: nss security update 2017-09-28 23:58:01 EDT

  None (edit)
Description Adam Mariš 2017-07-14 11:05:22 EDT
Potential use-after-free vulnerability in nss in TLS 1.2 server when verifying client authentication was found.

Upstream bug:

https://bugzilla.mozilla.org/show_bug.cgi?id=1377618
Comment 10 Doran Moppert 2017-09-28 00:25:39 EDT
Acknowledgments:

Name: the Mozilla project
Upstream: Martin Thomson
Comment 13 Tomas Hoger 2017-09-28 15:00:22 EDT
Created nss tracking bugs for this issue:

Affects: fedora-all [bug 1496926]
Comment 14 errata-xmlrpc 2017-09-28 19:58:47 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6
  Red Hat Enterprise Linux 7

Via RHSA-2017:2832 https://access.redhat.com/errata/RHSA-2017:2832

Note You need to log in before you can comment on or make changes to this bug.