Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-1938

Опубликовано: 26 янв. 2016
Источник: redhat
CVSS2: 2.6

Описание

The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging use of the (1) mp_div or (2) mp_exptmod function.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5nssWill not fix
Red Hat Enterprise Linux 6nss-softoknWill not fix
Red Hat Enterprise Linux 7nss-softoknWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-682
https://bugzilla.redhat.com/show_bug.cgi?id=1305159NSS: Errors in mp_div and mp_exptmod cryptographic functions

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 10 лет назад

The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging use of the (1) mp_div or (2) mp_exptmod function.

CVSS3: 6.5
nvd
около 10 лет назад

The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging use of the (1) mp_div or (2) mp_exptmod function.

CVSS3: 6.5
debian
около 10 лет назад

The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Secur ...

CVSS3: 6.5
github
больше 3 лет назад

The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging use of the (1) mp_div or (2) mp_exptmod function.

suse-cvrf
около 10 лет назад

Security update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nss

2.6 Low

CVSS2