PT-2016-1439 · Mozilla+4 · Firefox+5
Ekr
+1
·
Published
2016-01-26
·
Updated
2017-11-04
·
CVE-2016-1978
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Mozilla Network Security Services (NSS) versions prior to 3.21
Mozilla Firefox versions prior to 44.0
Description
A use-after-free issue in the ssl3 HandleECDHServerKeyExchange function allows remote attackers to cause a denial of service or possibly have other impacts by making an SSL handshake at a time of high memory consumption. This can occur during (1) DHE or (2) ECDHE handshake.
Recommendations
For Mozilla Network Security Services (NSS) versions prior to 3.21, update to version 3.21 or later.
For Mozilla Firefox versions prior to 44.0, update to version 44.0 or later.
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Firefox
Network Security Services
Red Hat
Suse
Ubuntu