CVE-2016-8635
published 2018-08-01CVE-2016-8635: It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement attack. An attacker could use this…
PriorityP430medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
2.02%
78.8th percentile
It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement attack. An attacker could use this flaw to recover private keys by confining the client DH key to small subgroup of the desired group.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nss | < nss 2:3.25-1 (bookworm) | nss 2:3.25-1 (bookworm) |
| mozilla | network_security_services | 3.21 – 3.21.4 | — |
| mozilla | nss | — | — |
| mozilla | nss | >= 0 < 2:3.25-1 | 2:3.25-1 |
| mozilla | nss | >= 0 < 2:3.25-1 | 2:3.25-1 |
| mozilla | nss | >= 0 < 2:3.25-1 | 2:3.25-1 |
| mozilla | nss | >= 0 < 2:3.25-1 | 2:3.25-1 |
| mozilla | nss | >= 0 < 2:3.26.2-0ubuntu0.14.04.3 | 2:3.26.2-0ubuntu0.14.04.3 |
| mozilla | nss | >= 0 < 2:3.26.2-0ubuntu0.16.04.2 | 2:3.26.2-0ubuntu0.16.04.2 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j6rc-c6gr-mf89: It was found that Diffie Hellman Client key exchange handling in NSS 3
ghsa_unreviewed·2022-05-13
CVE-2016-8635 [MEDIUM] CWE-358 GHSA-j6rc-c6gr-mf89: It was found that Diffie Hellman Client key exchange handling in NSS 3
It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement attack. An attacker could use this flaw to recover private keys by confining the client DH key to small subgroup of the desired group.
OSV
CVE-2016-8635: It was found that Diffie Hellman Client key exchange handling in NSS 3
osv·2018-08-01·CVSS 5.9
CVE-2016-8635 [MEDIUM] CVE-2016-8635: It was found that Diffie Hellman Client key exchange handling in NSS 3
It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement attack. An attacker could use this flaw to recover private keys by confining the client DH key to small subgroup of the desired group.
OSV
nss vulnerabilities
osv·2017-01-04·CVSS 7.5
CVE-2016-5285 [HIGH] nss vulnerabilities
nss vulnerabilities
It was discovered that NSS incorrectly handled certain invalid
Diffie-Hellman keys. A remote attacker could possibly use this flaw to
cause NSS to crash, resulting in a denial of service. This issue only
applied to Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.
(CVE-2016-5285)
Hubert Kario discovered that NSS incorrectly handled Diffie Hellman client
key exchanges. A remote attacker could possibly use this flaw to perform a
small subgroup confinement attack and recover private keys. This issue only
applied to Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.
(CVE-2016-8635)
Franziskus Kiefer discovered that NSS incorrectly mitigated certain timing
side-channel attacks. A remote attacker could possibly use this flaw to
recover private keys. (CVE-2016-
Ubuntu
NSS vulnerabilities
vendor_ubuntu·2017-01-04·CVSS 7.5
CVE-2016-5285 [HIGH] NSS vulnerabilities
Title: NSS vulnerabilities
Summary: Several security issues were fixed in NSS.
It was discovered that NSS incorrectly handled certain invalid
Diffie-Hellman keys. A remote attacker could possibly use this flaw to
cause NSS to crash, resulting in a denial of service. This issue only
applied to Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.
(CVE-2016-5285)
Hubert Kario discovered that NSS incorrectly handled Diffie Hellman client
key exchanges. A remote attacker could possibly use this flaw to perform a
small subgroup confinement attack and recover private keys. This issue only
applied to Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.
(CVE-2016-8635)
Franziskus Kiefer discovered that NSS incorrectly mitigated certain timing
side-channel attacks. A remote attacker coul
Red Hat
nss: small-subgroups attack flaw
vendor_redhat·2016-11-16·CVSS 5.3
CVE-2016-8635 [MEDIUM] nss: small-subgroups attack flaw
nss: small-subgroups attack flaw
It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement attack. An attacker could use this flaw to recover private keys by confining the client DH key to small subgroup of the desired group.
It was found that Diffie Hellman Client key exchange handling in NSS was vulnerable to small subgroup confinement attack. An attacker could use this flaw to recover private keys by confining the client DH key to small subgroup of the desired group.
Debian
CVE-2016-8635: nss - It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was ...
vendor_debian·2016·CVSS 5.3
CVE-2016-8635 [MEDIUM] CVE-2016-8635: nss - It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was ...
It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement attack. An attacker could use this flaw to recover private keys by confining the client DH key to small subgroup of the desired group.
Scope: local
bookworm: resolved (fixed in 2:3.25-1)
bullseye: resolved (fixed in 2:3.25-1)
forky: resolved (fixed in 2:3.25-1)
sid: resolved (fixed in 2:3.25-1)
trixie: resolved (fixed in 2:3.25-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-8635 nss: small-subgroups attack flaw
bugzilla·2016-11-04·CVSS 5.3
CVE-2016-8635 [MEDIUM] CVE-2016-8635 nss: small-subgroups attack flaw
CVE-2016-8635 nss: small-subgroups attack flaw
It was found that Diffie Hellman Client key exchange handling in NSS, was vulnerable to small subgroup confinement attack[1]. An attacker could use this flaw to recover private keys by confining the client DH key to small subgroup of the desired group.
[1] https://en.wikipedia.org/wiki/Small_subgroup_confinement_attack
Discussion:
Acknowledgments:
Name: Hubert Kario (Red Hat)
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 5
Via RHSA-2016:2779 https://rhn.redhat.com/errata/RHSA-2016-2779.html
Bugzilla
NSS 3.21.x branch still crashing with some DH keys, fix from bug 1306103 was apparently incomplete
bugzilla·2016-11-02
[MEDIUM] NSS 3.21.x branch still crashing with some DH keys, fix from bug 1306103 was apparently incomplete
NSS 3.21.x branch still crashing with some DH keys, fix from bug 1306103 was apparently incomplete
This is a follow-up to bug 1306103.
During testing Hubert identified and convinced Bob that the original fix introduced a new issue.
I'm just the messenger here, so I'll let Hubert and Bob explain the new issue. (Hubert, maybe you could simply copy/paste the relevant portions from the emails that you and Bob exchanged?).
I'm attaching a patch, which is based on Bob's suggestion. I assume that RH will take that patch for our Nov 8 update.
Should the official Mozilla ESR 45.x release planned for Nov 8 also pick up this fix?
Related is:
(In reply to Martin Thomson [:mt:] from bug 1306103 comment #16)
> After eyeballing the code, it looks like
> we narrowly avoid the bug on the client side
http://rhn.redhat.com/errata/RHSA-2016-2779.htmlhttp://www.securityfocus.com/bid/94346https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8635https://security.gentoo.org/glsa/201701-46http://rhn.redhat.com/errata/RHSA-2016-2779.htmlhttp://www.securityfocus.com/bid/94346https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8635https://security.gentoo.org/glsa/201701-46
2018-08-01
Published