CVE-2017-5462: Debian Linux

Medium severity, CVSS 5.3. EPSS: 2.6% chance of exploitation in the next 30 days.

A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS library has been updated to fix this issue to address this issue and Firefox ESR 52.1 has been updated with NSS version 3.28.4. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Mozilla Firefox: before 45.9.0 (fixed in 45.9.0); before 53.0 (fixed in 53.0); version 52.0 only
  • Mozilla Network Security Services: before 3.28.4 (fixed in 3.28.4)
  • Mozilla Thunderbird: before 52.1.0 (fixed in 52.1.0)

Published 2018-06-11. Last modified 2026-06-17.