CVE-2016-1938

CWE-310CWE-68213 documents8 sources
Severity
6.5MEDIUM
EPSS
1.0%
top 22.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 31
Latest updateMay 14

Description

The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging use of the (1) mp_div or (2) mp_exptmod function.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 3.9 | Impact: 2.5

Affected Packages6 packages

NVDmozilla/firefox43.0.4
NVDmozilla/nss3.20.1
Debiannss< 2:3.21-1+3
Ubuntunss< 2:3.21-0ubuntu0.14.04.1
NVDopensuse/leap42.1

🔴Vulnerability Details

5
GHSA
GHSA-xp2m-37gc-hr6h: The s_mp_div function in lib/freebl/mpi/mpi2022-05-14
OSV
thunderbird vulnerabilities2016-05-19
OSV
nss vulnerability2016-02-17
OSV
CVE-2016-1938: The s_mp_div function in lib/freebl/mpi/mpi2016-01-31
CVEList
CVE-2016-1938: The s_mp_div function in lib/freebl/mpi/mpi2016-01-31

📋Vendor Advisories

6
Ubuntu
Thunderbird vulnerabilities2016-05-19
Ubuntu
NSS regression2016-02-23
Ubuntu
NSS vulnerability2016-02-17
Ubuntu
Firefox vulnerabilities2016-01-27
Red Hat
NSS: Errors in mp_div and mp_exptmod cryptographic functions2016-01-26

💬Community

1
Bugzilla
CVE-2016-1938 Mozilla NSS: Errors in mp_div and mp_exptmod cryptographic functions2016-02-05
CVE-2016-1938 (MEDIUM CVSS 6.5) | The s_mp_div function in lib/freebl | cvebase.io