PT-2016-6342 · Mozilla+5 · Network Security Services+5

Kai Engert

+1

·

Published

2016-08-15

·

Updated

2020-01-09

·

CVE-2016-5285

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Mozilla Network Security Services (affected versions not specified)
Description A Null pointer dereference issue exists due to a missing NULL check in PK11 SignWithSymKey / ssl3 ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1844
CESA-2016_2779
CVE-2016-5285
RHSA-2016:2779
RHSA-2016_2779
SUSE-SU-2016:3014-1
SUSE-SU-2016:3080-1
SUSE-SU-2016:3105-1
SUSE-SU-2016_3014-1
USN-3163-1

Affected Products

Alt Linux
Centos
Network Security Services
Red Hat
Suse
Ubuntu