CVE Vulnerabilities

CVE-2016-1938

Published: Jan 31, 2016 | Modified: Oct 30, 2018
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM

The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging use of the (1) mp_div or (2) mp_exptmod function.

Affected Software

Name Vendor Start Version End Version
Leap Opensuse 42.1 (including) 42.1 (including)
Opensuse Opensuse 13.1 (including) 13.1 (including)
Opensuse Opensuse 13.2 (including) 13.2 (including)
Firefox Ubuntu devel *
Firefox Ubuntu precise *
Firefox Ubuntu trusty *
Firefox Ubuntu upstream *
Firefox Ubuntu vivid *
Firefox Ubuntu wily *
Firefox Ubuntu xenial *
Firefox Ubuntu yakkety *
Firefox Ubuntu zesty *
Nss Ubuntu precise *
Nss Ubuntu trusty *
Nss Ubuntu upstream *
Nss Ubuntu vivid *
Nss Ubuntu vivid/stable-phone-overlay *
Nss Ubuntu wily *
Thunderbird Ubuntu devel *
Thunderbird Ubuntu precise *
Thunderbird Ubuntu trusty *
Thunderbird Ubuntu upstream *
Thunderbird Ubuntu vivid *
Thunderbird Ubuntu wily *
Thunderbird Ubuntu xenial *
Thunderbird Ubuntu yakkety *
Thunderbird Ubuntu zesty *

References