CVE-2016-1978

Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.3 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
Affected Products (NVD)
VendorProductVersion
mozillafirefox
𝑥
≤ 43.0.4
mozillanetwork_security_services
𝑥
≤ 3.20.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
nss
bookworm
2:3.87.1-1
fixed
bullseye
2:3.61-1+deb11u3
fixed
bullseye (security)
2:3.61-1+deb11u4
fixed
jessie
not-affected
sid
2:3.105-2
fixed
trixie
2:3.105-2
fixed
wheezy
not-affected
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
firefox
precise
Fixed 44.0.2+build1-0ubuntu0.12.04.1
released
trusty
Fixed 44.0.2+build1-0ubuntu0.14.04.1
released
wily
Fixed 44.0.2+build1-0ubuntu0.15.10.1
released
xenial
not-affected
yakkety
not-affected
zesty
not-affected
nss
precise
Fixed 2:3.21-0ubuntu0.12.04.2
released
trusty
Fixed 2:3.21-0ubuntu0.14.04.1
released
wily
Fixed 2:3.21-0ubuntu0.15.10.1
released
xenial
not-affected
yakkety
not-affected
zesty
not-affected
thunderbird
precise
Fixed 1:38.8.0+build1-0ubuntu0.12.04.1
released
trusty
Fixed 1:38.8.0+build1-0ubuntu0.14.04.1
released
wily
Fixed 1:38.8.0+build1-0ubuntu0.15.10.1
released
xenial
Fixed 1:38.8.0+build1-0ubuntu0.16.04.1
released
yakkety
Fixed 1:38.8.0+build1-0ubuntu1
released
zesty
Fixed 1:38.8.0+build1-0ubuntu1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libfreebl3
suse enterprise sap 12
3.20.2-40.1
fixed
suse enterprise sap 12 SP1
3.20.2-40.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise server 12
3.20.2-40.1
fixed
suse enterprise server 12 SP1
3.20.2-40.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
libfreebl3-32bit
suse enterprise sap 12
3.20.2-40.1
fixed
suse enterprise sap 12 SP1
3.20.2-40.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise server 12
3.20.2-40.1
fixed
suse enterprise server 12 SP1
3.20.2-40.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
libfreebl3-hmac
suse enterprise sap 12
3.20.2-40.1
fixed
suse enterprise sap 12 SP1
3.20.2-40.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise server 12
3.20.2-40.1
fixed
suse enterprise server 12 SP1
3.20.2-40.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
libfreebl3-hmac-32bit
suse enterprise sap 12
3.20.2-40.1
fixed
suse enterprise sap 12 SP1
3.20.2-40.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise server 12
3.20.2-40.1
fixed
suse enterprise server 12 SP1
3.20.2-40.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
libsoftokn3
suse enterprise sap 12
3.20.2-40.1
fixed
suse enterprise sap 12 SP1
3.20.2-40.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise server 12
3.20.2-40.1
fixed
suse enterprise server 12 SP1
3.20.2-40.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
libsoftokn3-32bit
suse enterprise sap 12
3.20.2-40.1
fixed
suse enterprise sap 12 SP1
3.20.2-40.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise server 12
3.20.2-40.1
fixed
suse enterprise server 12 SP1
3.20.2-40.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
libsoftokn3-hmac
suse enterprise sap 12
3.20.2-40.1
fixed
suse enterprise sap 12 SP1
3.20.2-40.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise server 12
3.20.2-40.1
fixed
suse enterprise server 12 SP1
3.20.2-40.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
libsoftokn3-hmac-32bit
suse enterprise sap 12
3.20.2-40.1
fixed
suse enterprise sap 12 SP1
3.20.2-40.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise server 12
3.20.2-40.1
fixed
suse enterprise server 12 SP1
3.20.2-40.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
mozilla-nspr
suse enterprise sap 12
4.12-12.1
fixed
suse enterprise sap 12 SP1
4.12-12.1
fixed
suse enterprise server 12
4.12-12.1
fixed
suse enterprise server 12 SP1
4.12-12.1
fixed
mozilla-nspr-32bit
suse enterprise sap 12
4.12-12.1
fixed
suse enterprise sap 12 SP1
4.12-12.1
fixed
suse enterprise server 12
4.12-12.1
fixed
suse enterprise server 12 SP1
4.12-12.1
fixed
mozilla-nss
suse enterprise sap 12
3.20.2-40.1
fixed
suse enterprise sap 12 SP1
3.20.2-40.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise server 12
3.20.2-40.1
fixed
suse enterprise server 12 SP1
3.20.2-40.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
mozilla-nss-32bit
suse enterprise sap 12
3.20.2-40.1
fixed
suse enterprise sap 12 SP1
3.20.2-40.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise server 12
3.20.2-40.1
fixed
suse enterprise server 12 SP1
3.20.2-40.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
mozilla-nss-certs
suse enterprise sap 12
3.20.2-40.1
fixed
suse enterprise sap 12 SP1
3.20.2-40.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise server 12
3.20.2-40.1
fixed
suse enterprise server 12 SP1
3.20.2-40.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
mozilla-nss-certs-32bit
suse enterprise sap 12
3.20.2-40.1
fixed
suse enterprise sap 12 SP1
3.20.2-40.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise server 12
3.20.2-40.1
fixed
suse enterprise server 12 SP1
3.20.2-40.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
mozilla-nss-sysinit
suse enterprise sap 12
3.20.2-40.1
fixed
suse enterprise sap 12 SP1
3.20.2-40.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise server 12
3.20.2-40.1
fixed
suse enterprise server 12 SP1
3.20.2-40.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
mozilla-nss-sysinit-32bit
suse enterprise sap 12
3.20.2-40.1
fixed
suse enterprise sap 12 SP1
3.20.2-40.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise server 12
3.20.2-40.1
fixed
suse enterprise server 12 SP1
3.20.2-40.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
mozilla-nss-tools
suse enterprise sap 12
3.20.2-40.1
fixed
suse enterprise sap 12 SP1
3.20.2-40.1
fixed
suse enterprise sap 12 SP5
3.45-58.31.1
fixed
suse enterprise server 12
3.20.2-40.1
fixed
suse enterprise server 12 SP1
3.20.2-40.1
fixed
suse enterprise server 12 SP5
3.45-58.31.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
nspr
RHEL 6
0:4.11.0-0.1.el6_7
fixed
RHEL 7
0:4.11.0-1.el7_2
fixed
nspr-devel
RHEL 6
0:4.11.0-0.1.el6_7
fixed
RHEL 7
0:4.11.0-1.el7_2
fixed
nss
RHEL 6
0:3.21.0-0.3.el6_7
fixed
RHEL 7
0:3.21.0-9.el7_2
fixed
nss-devel
RHEL 6
0:3.21.0-0.3.el6_7
fixed
RHEL 7
0:3.21.0-9.el7_2
fixed
nss-pkcs11-devel
RHEL 6
0:3.21.0-0.3.el6_7
fixed
RHEL 7
0:3.21.0-9.el7_2
fixed
nss-softokn
RHEL 7
0:3.16.2.3-14.2.el7_2
fixed
nss-softokn-devel
RHEL 7
0:3.16.2.3-14.2.el7_2
fixed
nss-softokn-freebl
RHEL 7
0:3.16.2.3-14.2.el7_2
fixed
nss-softokn-freebl-devel
RHEL 7
0:3.16.2.3-14.2.el7_2
fixed
nss-sysinit
RHEL 6
0:3.21.0-0.3.el6_7
fixed
RHEL 7
0:3.21.0-9.el7_2
fixed
nss-tools
RHEL 6
0:3.21.0-0.3.el6_7
fixed
RHEL 7
0:3.21.0-9.el7_2
fixed
nss-util
RHEL 6
0:3.21.0-0.3.el6_7
fixed
RHEL 7
0:3.21.0-2.2.el7_2
fixed
nss-util-devel
RHEL 6
0:3.21.0-0.3.el6_7
fixed
RHEL 7
0:3.21.0-2.2.el7_2
fixed
References