CVE-2016-5285
published 2019-11-15CVE-2016-5285: A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey /…
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.28%
81.2th percentile
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| avaya | aura_application_enablement_services | — | — |
| avaya | aura_application_enablement_services | 6.1 – 6.3.3 | — |
| avaya | aura_application_server_5300 | — | — |
| avaya | aura_communication_manager | — | — |
| avaya | aura_communication_manager | 6.0 – 6.3.117.0 | — |
| avaya | aura_communication_manager_messagint | — | — |
| avaya | aura_conferencing | — | — |
| avaya | aura_conferencing | — | — |
| avaya | aura_conferencing | — | — |
| avaya | aura_experience_portal | 6.0 – 7.1 | — |
| avaya | aura_messaging | — | — |
| avaya | aura_messaging | — | — |
| avaya | aura_session_manager | — | — |
| avaya | aura_session_manager | — | — |
| avaya | aura_session_manager | 6.3 – 6.3.18 | — |
| avaya | aura_system_manager | 6.3 – 6.3.18 | — |
| avaya | aura_system_manager | 7.0 – 7.0.1.3 | — |
| avaya | aura_system_platform_firmware | 6.3 – 6.4.0 | — |
| avaya | aura_utility_services | 6.3 – 6.3.14 | — |
| avaya | aura_utility_services | 7.0 – 7.0.1.2 | — |
| avaya | breeze_platform | 3.0 – 3.2 | — |
| avaya | call_management_system | — | — |
| avaya | call_management_system | 18.0.0.1 – 18.0.0.2 | — |
| avaya | cs1000e_cs1000m_signaling_server_firmware | 7.0 – 7.6 | — |
| avaya | cs1000e_firmware | 7.0 – 7.6 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5p92-qfvf-9h9q: Null pointer dereference vulnerability exists in K11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime in NSS before 3
ghsa_unreviewed·2022-05-24
CVE-2016-5285 [MEDIUM] GHSA-5p92-qfvf-9h9q: Null pointer dereference vulnerability exists in K11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime in NSS before 3
Null pointer dereference vulnerability exists in K11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime in NSS before 3.26, which causes the TLS/SSL server using NSS to crash.
OSV
CVE-2016-5285: A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_Compute
osv·2019-11-15·CVSS 7.5
CVE-2016-5285 [HIGH] CVE-2016-5285: A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_Compute
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
OSV
nss vulnerabilities
osv·2017-01-04·CVSS 7.5
CVE-2016-5285 [HIGH] nss vulnerabilities
nss vulnerabilities
It was discovered that NSS incorrectly handled certain invalid
Diffie-Hellman keys. A remote attacker could possibly use this flaw to
cause NSS to crash, resulting in a denial of service. This issue only
applied to Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.
(CVE-2016-5285)
Hubert Kario discovered that NSS incorrectly handled Diffie Hellman client
key exchanges. A remote attacker could possibly use this flaw to perform a
small subgroup confinement attack and recover private keys. This issue only
applied to Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.
(CVE-2016-8635)
Franziskus Kiefer discovered that NSS incorrectly mitigated certain timing
side-channel attacks. A remote attacker could possibly use this flaw to
recover private keys. (CVE-2016-
Ubuntu
NSS vulnerabilities
vendor_ubuntu·2017-01-04·CVSS 7.5
CVE-2016-5285 [HIGH] NSS vulnerabilities
Title: NSS vulnerabilities
Summary: Several security issues were fixed in NSS.
It was discovered that NSS incorrectly handled certain invalid
Diffie-Hellman keys. A remote attacker could possibly use this flaw to
cause NSS to crash, resulting in a denial of service. This issue only
applied to Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.
(CVE-2016-5285)
Hubert Kario discovered that NSS incorrectly handled Diffie Hellman client
key exchanges. A remote attacker could possibly use this flaw to perform a
small subgroup confinement attack and recover private keys. This issue only
applied to Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.
(CVE-2016-8635)
Franziskus Kiefer discovered that NSS incorrectly mitigated certain timing
side-channel attacks. A remote attacker coul
Red Hat
nss: Missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime causes server crash
vendor_redhat·2016-11-16·CVSS 7.5
CVE-2016-5285 [HIGH] nss: Missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime causes server crash
nss: Missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime causes server crash
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
A NULL pointer dereference flaw was found in the way NSS handled invalid Diffie-Hellman keys. A remote client could use this flaw to crash a TLS/SSL server using NSS.
Debian
CVE-2016-5285: nss - A Null pointer dereference vulnerability exists in Mozilla Network Security Serv...
vendor_debian·2016·CVSS 7.5
CVE-2016-5285 [HIGH] CVE-2016-5285: nss - A Null pointer dereference vulnerability exists in Mozilla Network Security Serv...
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
Scope: local
bookworm: resolved (fixed in 2:3.25-1)
bullseye: resolved (fixed in 2:3.25-1)
forky: resolved (fixed in 2:3.25-1)
sid: resolved (fixed in 2:3.25-1)
trixie: resolved (fixed in 2:3.25-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-5285 nss: Missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime causes server crash [fedora-all]
bugzilla·2016-11-16·CVSS 7.5
CVE-2016-5285 [HIGH] CVE-2016-5285 nss: Missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime causes server crash [fedora-all]
CVE-2016-5285 nss: Missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime causes server crash [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
Bugzilla
CVE-2016-5285 nss: Missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime causes server crash
bugzilla·2016-10-12·CVSS 7.5
CVE-2016-5285 [HIGH] CVE-2016-5285 nss: Missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime causes server crash
CVE-2016-5285 nss: Missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime causes server crash
A flaw was found in the way a NSS server could be crashed remotely by a client sending an invalid DH key.
Discussion:
Upstream commit:
https://hg.mozilla.org/projects/nss/rev/45c047d18ac4
---
*** Bug 1380235 has been marked as a duplicate of this bug. ***
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 5
Via RHSA-2016:2779 https://rhn.redhat.com/errata/RHSA-2016-2779.html
---
Created nss tracking bugs for this issue:
Affects: fedora-all [bug 1395535]
---
*** Bug 1374803 has been marked as a duplicate of this bug. ***
http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00037.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00049.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2779.htmlhttp://www.securityfocus.com/bid/94349http://www.ubuntu.com/usn/USN-3163-1https://bto.bluecoat.com/security-advisory/sa137https://bugzilla.mozilla.org/show_bug.cgi?id=1306103https://security.gentoo.org/glsa/201701-46http://lists.opensuse.org/opensuse-security-announce/2016-12/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00037.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-12/msg00049.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2779.htmlhttp://www.securityfocus.com/bid/94349http://www.ubuntu.com/usn/USN-3163-1https://bto.bluecoat.com/security-advisory/sa137https://bugzilla.mozilla.org/show_bug.cgi?id=1306103https://security.gentoo.org/glsa/201701-46
2019-11-15
Published