Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-1938

Опубликовано: 31 янв. 2016
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.4
CVSS3: 6.5

Описание

The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging use of the (1) mp_div or (2) mp_exptmod function.

РелизСтатусПримечание
devel

released

44.0+build3-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [44.0+build3-0ubuntu0.14.04.1]]
precise

released

44.0+build3-0ubuntu0.12.04.1
precise/esm

DNE

precise was released [44.0+build3-0ubuntu0.12.04.1]
trusty

released

44.0+build3-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [44.0+build3-0ubuntu0.14.04.1]
upstream

released

44.0
vivid

released

44.0+build3-0ubuntu0.15.04.1
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

Показывать по

РелизСтатусПримечание
devel

not-affected

2:3.21-1ubuntu2
esm-infra-legacy/trusty

released

2:3.21-0ubuntu0.14.04.1
esm-infra/xenial

not-affected

2:3.21-1ubuntu2
precise

released

2:3.21-0ubuntu0.12.04.1
precise/esm

not-affected

2:3.21-0ubuntu0.12.04.1
trusty

released

2:3.21-0ubuntu0.14.04.1
trusty/esm

released

2:3.21-0ubuntu0.14.04.1
upstream

released

3.21
vivid

ignored

end of life
vivid/stable-phone-overlay

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

released

1:38.8.0+build1-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1:38.8.0+build1-0ubuntu0.14.04.1]]
precise

released

1:38.8.0+build1-0ubuntu0.12.04.1
precise/esm

DNE

precise was released [1:38.8.0+build1-0ubuntu0.12.04.1]
trusty

released

1:38.8.0+build1-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [1:38.8.0+build1-0ubuntu0.14.04.1]
upstream

released

38.8.0
vivid

ignored

end of life
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

Показывать по

EPSS

Процентиль: 69%
0.0059
Низкий

6.4 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

redhat
около 10 лет назад

The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging use of the (1) mp_div or (2) mp_exptmod function.

CVSS3: 6.5
nvd
около 10 лет назад

The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging use of the (1) mp_div or (2) mp_exptmod function.

CVSS3: 6.5
debian
около 10 лет назад

The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Secur ...

CVSS3: 6.5
github
больше 3 лет назад

The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging use of the (1) mp_div or (2) mp_exptmod function.

suse-cvrf
около 10 лет назад

Security update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nss

EPSS

Процентиль: 69%
0.0059
Низкий

6.4 Medium

CVSS2

6.5 Medium

CVSS3