Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-1978

Опубликовано: 13 мар. 2016
Источник: debian
EPSS Низкий

Описание

Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
iceweaselfixed44.0-1package
iceweaselnot-affectedjessiepackage
iceweaselnot-affectedwheezypackage
nssfixed2:3.21-1package

Примечания

  • Marked as fixed in 44.0-1 which would be the version fixing

  • the issue while using the bundled nss version. iceweasel for

  • unstable though used the system library.

  • https://www.mozilla.org/en-US/security/advisories/mfsa2016-15/

EPSS

Процентиль: 86%
0.02754
Низкий

Связанные уязвимости

CVSS3: 7.3
ubuntu
больше 9 лет назад

Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption.

redhat
больше 9 лет назад

Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption.

CVSS3: 7.3
nvd
больше 9 лет назад

Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption.

CVSS3: 7.3
github
больше 3 лет назад

Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption.

fstec
больше 9 лет назад

Уязвимость набора библиотек Network Security Services, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие

EPSS

Процентиль: 86%
0.02754
Низкий