CVE-2016-1938

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging use of the (1) mp_div or (2) mp_exptmod function.

References

http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00001.html

http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00002.html

http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00010.html

http://www.debian.org/security/2016/dsa-3688

http://www.mozilla.org/security/announce/2016/mfsa2016-07.html

http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html

http://www.securityfocus.com/bid/81955

http://www.securityfocus.com/bid/91787

http://www.securitytracker.com/id/1034825

http://www.ubuntu.com/usn/USN-2880-1

http://www.ubuntu.com/usn/USN-2880-2

http://www.ubuntu.com/usn/USN-2903-1

http://www.ubuntu.com/usn/USN-2903-2

http://www.ubuntu.com/usn/USN-2973-1

https://blog.fuzzing-project.org/37-Mozilla-NSS-Wrong-calculation-results-in-mp_div-and-mp_exptmod.html

https://bugzilla.mozilla.org/show_bug.cgi?id=1190248

https://bugzilla.mozilla.org/show_bug.cgi?id=1194947

https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.21_release_notes

https://github.com/hannob/bignum-fuzz/blob/master/CVE-2016-1938-nss-mp_div.c

https://github.com/hannob/bignum-fuzz/blob/master/CVE-2016-1938-nss-mp_exptmod.c

https://hg.mozilla.org/projects/nss/diff/a555bf0fc23a/lib/freebl/mpi/mpi.c

https://security.gentoo.org/glsa/201605-06

https://security.gentoo.org/glsa/201701-46

Details

Source: MITRE

Published: 2016-01-31

Updated: 2018-10-30

Type: CWE-310

Risk Information

CVSS v2

Base Score: 6.4

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Impact Score: 4.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Impact Score: 2.5

Exploitability Score: 3.9

Severity: MEDIUM

Tenable Plugins

View all (20 total)

IDNameProductFamilySeverity
96643GLSA-201701-46 : Mozilla Network Security Service (NSS): Multiple vulnerabilities (Logjam) (SLOTH)NessusGentoo Local Security Checks
high
93871Debian DSA-3688-1 : nss - security update (Logjam) (SLOTH)NessusDebian Local Security Checks
critical
802019Firefox < 44 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
critical
91379GLSA-201605-06 : Mozilla Products: Multiple vulnerabilities (Logjam) (SLOTH)NessusGentoo Local Security Checks
critical
91258Ubuntu 12.04 LTS / 14.04 LTS / 15.10 / 16.04 LTS : thunderbird vulnerabilities (USN-2973-1)NessusUbuntu Local Security Checks
high
91242Debian DLA-480-1 : nss security updateNessusDebian Local Security Checks
critical
89766FreeBSD : NSS -- multiple vulnerabilities (75091516-6f4b-4059-9884-6727023dc366)NessusFreeBSD Local Security Checks
high
89021SUSE SLES11 Security Update : MozillaFirefox, MozillaFirefox-branding-SLED, MozillaFirefox-branding-SLES-for-VMware, mozilla-nss (SUSE-SU-2016:0584-1) (SLOTH)NessusSuSE Local Security Checks
critical
88938Debian DLA-427-1 : nss security updateNessusDebian Local Security Checks
medium
88928Ubuntu 12.04 LTS : nss regression (USN-2903-2)NessusUbuntu Local Security Checks
medium
9075Mozilla Firefox < 44.0 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
critical
88838Ubuntu 12.04 LTS / 14.04 LTS / 15.10 : nss vulnerability (USN-2903-1)NessusUbuntu Local Security Checks
medium
88637Ubuntu 12.04 LTS / 14.04 LTS / 15.10 : firefox regression (USN-2880-2)NessusUbuntu Local Security Checks
critical
88620SUSE SLED12 / SLES12 Security Update : MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nss (SUSE-SU-2016:0338-1)NessusSuSE Local Security Checks
critical
88619SUSE SLED11 / SLES11 Security Update : MozillaFirefox, MozillaFirefox-branding-SLED, mozilla-nss (SUSE-SU-2016:0334-1)NessusSuSE Local Security Checks
critical
88552openSUSE Security Update : Mozilla Firefox (openSUSE-2016-131)NessusSuSE Local Security Checks
critical
88549openSUSE Security Update : the MozillaFirefox / mozilla-nss and mozilla-nspr (openSUSE-2016-128)NessusSuSE Local Security Checks
critical
88461Firefox < 44 Multiple VulnerabilitiesNessusWindows
critical
88459Firefox < 44 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
88456Ubuntu 12.04 LTS / 14.04 LTS / 15.04 / 15.10 : firefox vulnerabilities (USN-2880-1)NessusUbuntu Local Security Checks
critical