CVE-2016-3099
published 2017-06-08CVE-2016-3099: mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation…
PriorityP342high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
1.72%
74.8th percentile
mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to force the use of ciphers that were not intended to be enabled.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6rg6-w3xx-cvm5: mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Wor
ghsa_unreviewed·2022-05-17
CVE-2016-3099 [HIGH] CWE-327 GHSA-6rg6-w3xx-cvm5: mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Wor
mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to force the use of ciphers that were not intended to be enabled.
OSV
CVE-2016-3099: mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Wor
osv·2017-06-08·CVSS 7.5
CVE-2016-3099 [HIGH] CVE-2016-3099: mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Wor
mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to force the use of ciphers that were not intended to be enabled.
OSV
linux-lts-xenial vulnerabilities
osv·2016-10-11·CVSS 5.1
linux-lts-xenial vulnerabilities
linux-lts-xenial vulnerabilities
USN-3099-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Vladimír Beneš discovered an unbounded recursion in the VLAN and TEB
Generic Receive Offload (GRO) processing implementations in the Linux
kernel, A remote attacker could use this to cause a stack corruption,
leading to a denial of service (system crash). (CVE-2016-7039)
Marco Grassi discovered a use-after-free condition could occur in the TCP
retransmit queue handling code in the Linux kernel. A local attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2016-6828)
Pengfei Wang discovered
Red Hat
mod_nss: Invalid handling of +CIPHER operator
vendor_redhat·2016-04-05·CVSS 7.5
CVE-2016-3099 [HIGH] CWE-392 mod_nss: Invalid handling of +CIPHER operator
mod_nss: Invalid handling of +CIPHER operator
mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to force the use of ciphers that were not intended to be enabled.
A flaw was found in the way mod_nss parsed certain OpenSSL-style cipher strings. As a result, mod_nss could potentially use ciphers that were not intended to be enabled.
Package: mod_nss (Red Hat Certificate System 8) - Will not fix
Package: mod_nss (Red Hat Enterprise Linux 5) - Will not fix
Package: mod_nss (Red Hat Enterprise Linux 6) - Will not fix
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3099 mod_nss: Invalid handling of +CIPHER operator [fedora-all]
bugzilla·2016-04-05·CVSS 7.5
CVE-2016-3099 [HIGH] CVE-2016-3099 mod_nss: Invalid handling of +CIPHER operator [fedora-all]
CVE-2016-3099 mod_nss: Invalid handling of +CIPHER operator [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedor
Bugzilla
CVE-2016-3099 mod_nss: Invalid handling of +CIPHER operator
bugzilla·2016-03-18·CVSS 7.5
CVE-2016-3099 [HIGH] CVE-2016-3099 mod_nss: Invalid handling of +CIPHER operator
CVE-2016-3099 mod_nss: Invalid handling of +CIPHER operator
It was reported that +CIPHER operator in OpenSSL changes the order of a cipher. Since cipher ordering isn't supported in NSS, the mod_nss code was supposed to return an error. Instead it returned the result of processing up to that point. Default OpenSSL cipher string:
!SSLv2:kEECDH:kRSA:kEDH:kPSK:+3DES:!aNULL:!eNULL:!MD5:!EXP:!RC4:!SEED:!IDEA:!DES
Would not properly exclude anything because only the first 5 elements would be examined.
Discussion:
Acknowledgments:
Name: Rob Crittenden (Red Hat)
---
Created mod_nss tracking bugs for this issue:
Affects: fedora-all [bug 1323914]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:2602 https://rhn.redhat.com/errata/RHSA-2
http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183102.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-April/183129.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-May/184345.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2602.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1319052http://lists.fedoraproject.org/pipermail/package-announce/2016-April/183102.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-April/183129.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-May/184345.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2602.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1319052
2017-06-08
Published