CVE-2016-1978
published 2016-03-13CVE-2016-1978: Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla…
PriorityP335high7.3CVSS 3.0
AVNACLPRNUINSUCLILAL
EPSS
2.39%
82.0th percentile
Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nss | < nss 2:3.21-1 (bookworm) | nss 2:3.21-1 (bookworm) |
| mozilla | firefox | <= 43.0.4 | — |
| mozilla | network_security_services | <= 3.20.1 | — |
| mozilla | nss | >= 0 < 2:3.21-1 | 2:3.21-1 |
| mozilla | nss | >= 0 < 2:3.21-1 | 2:3.21-1 |
| mozilla | nss | >= 0 < 2:3.21-1 | 2:3.21-1 |
| mozilla | nss | >= 0 < 2:3.21-1 | 2:3.21-1 |
| mozilla | thunderbird | >= 0 < 1:38.8.0+build1-0ubuntu0.14.04.1 | 1:38.8.0+build1-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:38.8.0+build1-0ubuntu0.16.04.1 | 1:38.8.0+build1-0ubuntu0.16.04.1 |
CVSS provenance
nvdv3.07.3HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.3HIGH
vendor_debian7.3HIGH
vendor_redhat7.3HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f6w7-986w-qhfq: Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3
ghsa_unreviewed·2022-05-17
CVE-2016-1978 [HIGH] GHSA-f6w7-986w-qhfq: Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3
Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption.
OSV
thunderbird vulnerabilities
osv·2016-05-19·CVSS 6.5
CVE-2016-2805 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
Christian Holler, Tyson Smith, and Phil Ringalda discovered multiple
memory safety issues in Thunderbird. If a user were tricked in to opening
a specially crafted message, an attacker could potentially exploit these
to cause a denial of service via application crash, or execute arbitrary
code. (CVE-2016-2805, CVE-2016-2807)
Hanno Böck discovered that calculations with mp_div and mp_exptmod in NSS
produce incorrect results in some circumstances, resulting in
cryptographic weaknesses. (CVE-2016-1938)
A use-after-free was discovered in ssl3_HandleECDHServerKeyExchange in
NSS. A remote attacker could potentially exploit this to cause a denial of
service via application crash, or execute arbitrary code. (CVE-2016-1978)
A use-after-free was discovered in PK11_Impo
OSV
CVE-2016-1978: Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3
osv·2016-03-13·CVSS 7.3
CVE-2016-1978 [HIGH] CVE-2016-1978: Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3
Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2016-05-19·CVSS 6.5
CVE-2016-1938 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Christian Holler, Tyson Smith, and Phil Ringalda discovered multiple
memory safety issues in Thunderbird. If a user were tricked in to opening
a specially crafted message, an attacker could potentially exploit these
to cause a denial of service via application crash, or execute arbitrary
code. (CVE-2016-2805, CVE-2016-2807)
Hanno Böck discovered that calculations with mp_div and mp_exptmod in NSS
produce incorrect results in some circumstances, resulting in
cryptographic weaknesses. (CVE-2016-1938)
A use-after-free was discovered in ssl3_HandleECDHServerKeyExchange in
NSS. A remote attacker could potentially exploit this to cause a denial of
service via application crash, or execute arbitrary
Red Hat
nss: Use-after-free in NSS during SSL connections in low memory (MFSA 2016-15)
vendor_redhat·2016-03-08·CVSS 7.3
CVE-2016-1978 [HIGH] nss: Use-after-free in NSS during SSL connections in low memory (MFSA 2016-15)
nss: Use-after-free in NSS during SSL connections in low memory (MFSA 2016-15)
Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption.
A use-after-free flaw was found in the way NSS handled DHE (Diffie–Hellman key exchange) and ECDHE (Elliptic Curve Diffie-Hellman key exchange) handshake messages. A remote attacker could send a specially crafted handshake message that, when parsed by an application linked against NSS, would cause that application to crash or, under certain special conditions, e
Debian
CVE-2016-1978: nss - Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in...
vendor_debian·2016·CVSS 7.3
CVE-2016-1978 [HIGH] CVE-2016-1978: nss - Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in...
Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption.
Scope: local
bookworm: resolved (fixed in 2:3.21-1)
bullseye: resolved (fixed in 2:3.21-1)
forky: resolved (fixed in 2:3.21-1)
sid: resolved (fixed in 2:3.21-1)
trixie: resolved (fixed in 2:3.21-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-1979 CVE-2016-1978 nss: various flaws [fedora-all]
bugzilla·2016-03-09·CVSS 7.3
CVE-2016-1979 [HIGH] CVE-2016-1979 CVE-2016-1978 nss: various flaws [fedora-all]
CVE-2016-1979 CVE-2016-1978 nss: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
Bugzilla
CVE-2016-1978 nss: Use-after-free in NSS during SSL connections in low memory (MFSA 2016-15)
bugzilla·2016-03-08·CVSS 7.3
CVE-2016-1978 [HIGH] CVE-2016-1978 nss: Use-after-free in NSS during SSL connections in low memory (MFSA 2016-15)
CVE-2016-1978 nss: Use-after-free in NSS during SSL connections in low memory (MFSA 2016-15)
Mozilla developer Eric Rescorla reported that a failed allocation during DHE and ECDHE handshakes would lead to a use-after-free vulnerability.
External Reference:
https://www.mozilla.org/security/announce/2016/mfsa2016-15.html
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Eric Rescorla
---
Created nss tracking bugs for this issue:
Affects: fedora-all [bug 1316003]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:0591 https://rhn.redhat.com/errata/RHSA-2016-0591.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:0685 https://rhn.redhat.com/errata/RHSA-2016
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00050.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00068.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00093.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0591.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0684.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0685.htmlhttp://www.debian.org/security/2016/dsa-3688http://www.mozilla.org/security/announce/2016/mfsa2016-15.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/84275http://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1035258http://www.ubuntu.com/usn/USN-2973-1https://bto.bluecoat.com/security-advisory/sa124https://bugzilla.mozilla.org/show_bug.cgi?id=1209546https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.21_release_noteshttps://security.gentoo.org/glsa/201605-06http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00027.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00050.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00068.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00093.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0591.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0684.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0685.htmlhttp://www.debian.org/security/2016/dsa-3688http://www.mozilla.org/security/announce/2016/mfsa2016-15.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/84275http://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1035258http://www.ubuntu.com/usn/USN-2973-1https://bto.bluecoat.com/security-advisory/sa124https://bugzilla.mozilla.org/show_bug.cgi?id=1209546https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.21_release_noteshttps://security.gentoo.org/glsa/201605-06
2016-03-13
Published