yocto ▾
›
master ▾
›
vulnerability
›
CVE-2017-11698
Component Overview
Vulnerability Overview
Name
CVE-2017-11698
Source
NVD (
link
)
Debian (
link
)
Description
Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.
CWEs
CWE-119
Published Date
Dec 27, 2017
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://packetstormsecurity.com/files/143735/NSS-Buffer-Overflows-Floating-Point-Exception.html
VDB Entry
http://seclists.org/fulldisclosure/2017/Aug/17
Exploit
http://www.geeknik.net/9brdqk6xu
Exploit
http://www.securityfocus.com/bid/100345
VDB Entry
http://www.securitytracker.com/id/1039153
VDB Entry
http://packetstormsecurity.com/files/143735/NSS-Buffer-Overflows-Floating-Point-Exception.html
VDB Entry
http://seclists.org/fulldisclosure/2017/Aug/17
Exploit
http://www.geeknik.net/9brdqk6xu
Exploit
http://www.securityfocus.com/bid/100345
VDB Entry
http://www.securitytracker.com/id/1039153
VDB Entry
Analysis
#
Affected Component
Analysis
nss
False Positive
Vulnerability Ratings
#
7.8
other
4.6
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
nss
openwrt
master
3.125-r1
Not Affected
nss
openwrt
openwrt-25.12
3.112-r1
Not Affected
nss
yocto
kirkstone
3.74
Not Affected
nss
yocto
scarthgap
3.98
False Positive