CVE-2016-1978

10 documents8 sources
Severity
7.3HIGH
EPSS
2.5%
top 14.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 13
Latest updateMay 17

Description

Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 3.9 | Impact: 3.4

Affected Packages3 packages

NVDmozilla/firefox43.0.4
Debiannss< 2:3.21-1+3

🔴Vulnerability Details

4
GHSA
GHSA-f6w7-986w-qhfq: Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 32022-05-17
OSV
thunderbird vulnerabilities2016-05-19
OSV
CVE-2016-1978: Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 32016-03-13
CVEList
CVE-2016-1978: Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 32016-03-13

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2016-05-19
Red Hat
nss: Use-after-free in NSS during SSL connections in low memory (MFSA 2016-15)2016-03-08
Debian
CVE-2016-1978: nss - Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in...2016

💬Community

2
Bugzilla
CVE-2016-1979 CVE-2016-1978 nss: various flaws [fedora-all]2016-03-09
Bugzilla
CVE-2016-1978 nss: Use-after-free in NSS during SSL connections in low memory (MFSA 2016-15)2016-03-08