Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

Red Hat: RHSA-2024:2203-02 Critical: libpng Buffer Overflow Vulnerability

red hat
Calendar Grey April 20, 2017
Scroller Redhat
An essential nss-util patch has been launched for Red Hat Enterprise Linux. Discover the implications and resolutions it offers.
An update for nss-util is now available for Red Hat Enterprise Linux 6.2 Advanced Update Support, Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5...

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

The nss-util packages provide utilities for use with the Network Security Services (NSS) libraries.
Security Fix(es):
* An out-of-bounds write flaw was found in the way NSS performed certain Base64-decoding operations. An attacker could use this flaw to create a specially crafted certificate which, when parsed by NSS, could cause it to crash or execute arbitrary code, using the permissions of the user running an application compiled against the NSS library. (CVE-2017-5461)
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Ronald Crane as the original reporter.

References

https://access.redhat.com/security/cve/CVE-2017-5461 https://access.redhat.com/security/updates/classification#critical

Package List

Red Hat Enterprise Linux HPC Node EUS (v. 6.7):
Source: nss-util-3.21.4-1.el6_7.src.rpm
x86_64: nss-util-3.21.4-1.el6_7.i686.rpm nss-util-3.21.4-1.el6_7.x86_64.rpm nss-util-debuginfo-3.21.4-1.el6_7.i686.rpm nss-util-debuginfo-3.21.4-1.el6_7.x86_64.rpm
Red Hat Enterprise Linux HPC Node Optional EUS (v. 6.7):
x86_64: nss-util-debuginfo-3.21.4-1.el6_7.i686.rpm nss-util-debuginfo-3.21.4-1.el6_7.x86_64.rpm nss-util-devel-3.21.4-1.el6_7.i686.rpm nss-util-devel-3.21.4-1.el6_7.x86_64.rpm
Red Hat Enterprise Linux Server AUS (v. 6.2):
Source: nss-util-3.13.1-11.el6_2.src.rpm
x86_64: nss-util-3.13.1-11.el6_2.i686.rpm nss-util-3.13.1-11.el6_2.x86_64.rpm nss-util-debuginfo-3.13.1-11.el6_2.i686.rpm nss-util-debuginfo-3.13.1-11.el6_2.x86_64.rpm nss-util-devel-3.13.1-11.el6_2.i686.rpm nss-util-devel-3.13.1-11.el6_2.x86_64.rpm
Red Hat Enterprise Linux Server AUS (v. 6.4):
Source: nss-util-3.14.3-9.el6_4.src.rpm
x86_64: nss-util-3.14.3-9.el6_4.i686.rpm nss-util-3.14.3-9.el6_4.x86_64.rpm nss-util-debuginfo-3.14.3-9.el6_4.i686.rpm nss-util-debuginfo-3.14.3-9.el6_4.x86_64.rpm nss-util-devel-3.14.3-9.el6_4.i686.rpm nss-util-devel-3.14.3-9.el6_4.x86_64.rpm
Red Hat Enterprise Linux Server AUS (v. 6.5):
Source: nss-util-3.16.1-5.el6_5.src.rpm
x86_64: nss-util-3.16.1-5.el6_5.i686.rpm

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2017:1102-01
Product: Red Hat Enterprise Linux
Issue date: 2017-04-20

Topic

An update for nss-util is now available for Red Hat Enterprise Linux 6.2Advanced Update Support, Red Hat Enterprise Linux 6.4 Advanced UpdateSupport, Red Hat Enterprise Linux 6.5 Advanced Update Support, Red HatEnterprise Linux 6.5 Telco Extended Update Support, Red Hat EnterpriseLinux 6.6 Advanced Update Support, Red Hat Enterprise Linux 6.6 TelcoExtended Update Support, Red Hat Enterprise Linux 6.7 Extended UpdateSupport, and Red Hat Enterprise Linux 7.2 Extended Update Support.Red Hat Product Security has rated this update as having a security impactof Critical. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Enterprise Linux ComputeNode EUS (v. 7.2) - x86_64

Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.2) - x86_64

Red Hat Enterprise Linux HPC Node EUS (v. 6.7) - x86_64

Red Hat Enterprise Linux HPC Node Optional EUS (v. 6.7) - x86_64

Red Hat Enterprise Linux Server AUS (v. 6.2) - x86_64

Red Hat Enterprise Linux Server AUS (v. 6.4) - x86_64

Red Hat Enterprise Linux Server AUS (v. 6.5) - x86_64

Red Hat Enterprise Linux Server AUS (v. 6.6) - x86_64

Red Hat Enterprise Linux Server EUS (v. 6.7) - i386, ppc64, s390x, x86_64

Red Hat Enterprise Linux Server EUS (v. 7.2) - ppc64, ppc64le, s390x, x86_64

Red Hat Enterprise Linux Server TUS (v. 6.5) - x86_64

Red Hat Enterprise Linux Server TUS (v. 6.6) - x86_64

Bugs Fixed

1440080 - CVE-2017-5461 nss: Write beyond bounds caused by bugs in Base64 de/encoding in nssb64d.c and nssb64e.c (MFSA 2017-10)

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.