CVE-2016-9074
published 2018-06-11CVE-2016-9074: An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NSS) 3.26.1…
PriorityP428medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
2.45%
82.6th percentile
An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NSS) 3.26.1. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | firefox-esr | < firefox-esr 45.5.0esr-1 (bookworm) | firefox-esr 45.5.0esr-1 (bookworm) |
| debian | nss | < firefox-esr 45.5.0esr-1 (bookworm) | firefox-esr 45.5.0esr-1 (bookworm) |
| mozilla | firefox | < 45.5.0 | 45.5.0 |
| mozilla | firefox | < 50.0 | 50.0 |
| mozilla | firefox | >= unspecified < 50 | 50 |
| mozilla | firefox_esr | >= unspecified < 45.5 | 45.5 |
| mozilla | nss | >= 0 < 2:3.26.2-1 | 2:3.26.2-1 |
| mozilla | nss | >= 0 < 2:3.26.2-1 | 2:3.26.2-1 |
| mozilla | nss | >= 0 < 2:3.26.2-1 | 2:3.26.2-1 |
| mozilla | nss | >= 0 < 2:3.26.2-1 | 2:3.26.2-1 |
| mozilla | nss | >= 0 < 2:3.26.2-0ubuntu0.14.04.3 | 2:3.26.2-0ubuntu0.14.04.3 |
| mozilla | nss | >= 0 < 2:3.26.2-0ubuntu0.16.04.2 | 2:3.26.2-0ubuntu0.16.04.2 |
| mozilla | thunderbird | < 45.5.0 | 45.5.0 |
| mozilla | thunderbird | >= unspecified < 45.5 | 45.5 |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wwm5-654g-jj42: An existing mitigation of timing side-channel attacks is insufficient in some circumstances
ghsa_unreviewed·2022-05-14
CVE-2016-9074 [MEDIUM] CWE-200 GHSA-wwm5-654g-jj42: An existing mitigation of timing side-channel attacks is insufficient in some circumstances
An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NSS) 3.26.1. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
OSV
CVE-2016-9074: An existing mitigation of timing side-channel attacks is insufficient in some circumstances
osv·2018-06-11·CVSS 5.9
CVE-2016-9074 [MEDIUM] CVE-2016-9074: An existing mitigation of timing side-channel attacks is insufficient in some circumstances
An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NSS) 3.26.1. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
OSV
nss vulnerabilities
osv·2017-01-04·CVSS 7.5
CVE-2016-5285 [HIGH] nss vulnerabilities
nss vulnerabilities
It was discovered that NSS incorrectly handled certain invalid
Diffie-Hellman keys. A remote attacker could possibly use this flaw to
cause NSS to crash, resulting in a denial of service. This issue only
applied to Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.
(CVE-2016-5285)
Hubert Kario discovered that NSS incorrectly handled Diffie Hellman client
key exchanges. A remote attacker could possibly use this flaw to perform a
small subgroup confinement attack and recover private keys. This issue only
applied to Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.
(CVE-2016-8635)
Franziskus Kiefer discovered that NSS incorrectly mitigated certain timing
side-channel attacks. A remote attacker could possibly use this flaw to
recover private keys. (CVE-2016-
Ubuntu
NSS vulnerabilities
vendor_ubuntu·2017-01-04·CVSS 7.5
CVE-2016-5285 [HIGH] NSS vulnerabilities
Title: NSS vulnerabilities
Summary: Several security issues were fixed in NSS.
It was discovered that NSS incorrectly handled certain invalid
Diffie-Hellman keys. A remote attacker could possibly use this flaw to
cause NSS to crash, resulting in a denial of service. This issue only
applied to Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.
(CVE-2016-5285)
Hubert Kario discovered that NSS incorrectly handled Diffie Hellman client
key exchanges. A remote attacker could possibly use this flaw to perform a
small subgroup confinement attack and recover private keys. This issue only
applied to Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.
(CVE-2016-8635)
Franziskus Kiefer discovered that NSS incorrectly mitigated certain timing
side-channel attacks. A remote attacker coul
Red Hat
nss: Insufficient timing side-channel resistance in divSpoiler
vendor_redhat·2016-11-15·CVSS 5.9
CVE-2016-9074 [MEDIUM] CWE-385 nss: Insufficient timing side-channel resistance in divSpoiler
nss: Insufficient timing side-channel resistance in divSpoiler
An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NSS) 3.26.1. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
Package: nss (Red Hat Enterprise Linux 5) - Will not fix
Package: nss (Red Hat Enterprise Linux 6) - Will not fix
Package: nss (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2016-9074: firefox-esr - An existing mitigation of timing side-channel attacks is insufficient in some ci...
vendor_debian·2016·CVSS 5.9
CVE-2016-9074 [MEDIUM] CVE-2016-9074: firefox-esr - An existing mitigation of timing side-channel attacks is insufficient in some ci...
An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NSS) 3.26.1. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
Scope: local
bookworm: resolved (fixed in 45.5.0esr-1)
bullseye: resolved (fixed in 45.5.0esr-1)
forky: resolved (fixed in 45.5.0esr-1)
sid: resolved (fixed in 45.5.0esr-1)
trixie: resolved (fixed in 45.5.0esr-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9074 nss: Insufficient timing side-channel resistance in divSpoiler [fedora-all]
bugzilla·2016-11-18·CVSS 5.9
CVE-2016-9074 [MEDIUM] CVE-2016-9074 nss: Insufficient timing side-channel resistance in divSpoiler [fedora-all]
CVE-2016-9074 nss: Insufficient timing side-channel resistance in divSpoiler [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2016-9074 nss: Insufficient timing side-channel resistance in divSpoiler
bugzilla·2016-11-18·CVSS 5.9
CVE-2016-9074 [MEDIUM] CVE-2016-9074 nss: Insufficient timing side-channel resistance in divSpoiler
CVE-2016-9074 nss: Insufficient timing side-channel resistance in divSpoiler
An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NSS) 3.26.1.
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2016-89/#CVE-2016-9074
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Franziskus Kiefer
---
Created nss tracking bugs for this issue:
Affects: fedora-all [bug 1396550]
---
Upstream commit:
https://hg.mozilla.org/projects/nss/rev/1e202f0a01b9
http://www.securityfocus.com/bid/94341http://www.securitytracker.com/id/1037298https://bugzilla.mozilla.org/show_bug.cgi?id=1293334https://security.gentoo.org/glsa/201701-15https://security.gentoo.org/glsa/201701-46https://www.debian.org/security/2016/dsa-3730https://www.mozilla.org/security/advisories/mfsa2016-89/https://www.mozilla.org/security/advisories/mfsa2016-90/https://www.mozilla.org/security/advisories/mfsa2016-93/http://www.securityfocus.com/bid/94341http://www.securitytracker.com/id/1037298https://bugzilla.mozilla.org/show_bug.cgi?id=1293334https://security.gentoo.org/glsa/201701-15https://security.gentoo.org/glsa/201701-46https://www.debian.org/security/2016/dsa-3730https://www.mozilla.org/security/advisories/mfsa2016-89/https://www.mozilla.org/security/advisories/mfsa2016-90/https://www.mozilla.org/security/advisories/mfsa2016-93/
2018-06-11
Published