CVE-2016-3099

Severity
7.5HIGH
EPSS
0.4%
top 41.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 8
Latest updateMay 17

Description

mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to force the use of ciphers that were not intended to be enabled.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

🔴Vulnerability Details

4
GHSA
GHSA-6rg6-w3xx-cvm5: mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Wor2022-05-17
OSV
CVE-2016-3099: mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Wor2017-06-08
CVEList
CVE-2016-3099: mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Wor2017-06-08
OSV
linux-lts-xenial vulnerabilities2016-10-11

📋Vendor Advisories

1
Red Hat
mod_nss: Invalid handling of +CIPHER operator2016-04-05

💬Community

2
Bugzilla
CVE-2016-3099 mod_nss: Invalid handling of +CIPHER operator [fedora-all]2016-04-05
Bugzilla
CVE-2016-3099 mod_nss: Invalid handling of +CIPHER operator2016-03-18