CVE-2017-5462

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-5462
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-5462.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-5462
Downstream
Related
Published
2018-06-11T21:29:07Z
Modified
2025-08-09T19:01:28Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS library has been updated to fix this issue to address this issue and Firefox ESR 52.1 has been updated with NSS version 3.28.4. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

References

Affected packages