Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-1938

Опубликовано: 26 янв. 2016
Источник: redhat
CVSS2: 2.6
EPSS Низкий

Описание

The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging use of the (1) mp_div or (2) mp_exptmod function.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5nssWill not fix
Red Hat Enterprise Linux 6nss-softoknWill not fix
Red Hat Enterprise Linux 7nss-softoknWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-682
https://bugzilla.redhat.com/show_bug.cgi?id=1305159NSS: Errors in mp_div and mp_exptmod cryptographic functions

EPSS

Процентиль: 87%
0.03121
Низкий

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 10 лет назад

The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging use of the (1) mp_div or (2) mp_exptmod function.

CVSS3: 6.5
nvd
больше 10 лет назад

The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging use of the (1) mp_div or (2) mp_exptmod function.

CVSS3: 6.5
debian
больше 10 лет назад

The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Secur ...

CVSS3: 6.5
github
около 4 лет назад

The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging use of the (1) mp_div or (2) mp_exptmod function.

suse-cvrf
больше 10 лет назад

Security update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nss

EPSS

Процентиль: 87%
0.03121
Низкий

2.6 Low

CVSS2