Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Firefox | Mozilla | * | 43.0.4 (including) |
Red Hat Enterprise Linux 5 | RedHat | nspr-0:4.11.0-1.el5_11 | * |
Red Hat Enterprise Linux 5 | RedHat | nss-0:3.21.0-6.el5_11 | * |
Red Hat Enterprise Linux 6 | RedHat | nspr-0:4.11.0-0.1.el6_7 | * |
Red Hat Enterprise Linux 6 | RedHat | nss-0:3.21.0-0.3.el6_7 | * |
Red Hat Enterprise Linux 6 | RedHat | nss-util-0:3.21.0-0.3.el6_7 | * |
Red Hat Enterprise Linux 7 | RedHat | nspr-0:4.11.0-1.el7_2 | * |
Red Hat Enterprise Linux 7 | RedHat | nss-0:3.21.0-9.el7_2 | * |
Red Hat Enterprise Linux 7 | RedHat | nss-softokn-0:3.16.2.3-14.2.el7_2 | * |
Red Hat Enterprise Linux 7 | RedHat | nss-util-0:3.21.0-2.2.el7_2 | * |
Firefox | Ubuntu | precise | * |
Firefox | Ubuntu | trusty | * |
Firefox | Ubuntu | upstream | * |
Firefox | Ubuntu | wily | * |
Nss | Ubuntu | precise | * |
Nss | Ubuntu | trusty | * |
Nss | Ubuntu | upstream | * |
Nss | Ubuntu | vivid/stable-phone-overlay | * |
Nss | Ubuntu | wily | * |
Thunderbird | Ubuntu | devel | * |
Thunderbird | Ubuntu | precise | * |
Thunderbird | Ubuntu | trusty | * |
Thunderbird | Ubuntu | upstream | * |
Thunderbird | Ubuntu | wily | * |
Thunderbird | Ubuntu | xenial | * |
Thunderbird | Ubuntu | yakkety | * |
Thunderbird | Ubuntu | zesty | * |