CVE-2016-1938

Description

The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging use of the (1) mp_div or (2) mp_exptmod function.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.59

Associated Vulnerability

VulnerabilityOS Platform
Update for Mozilla Firefox (44.0)Windows
Update for Mozilla Firefox x64 (44.0)Windows
Update for Mozilla Firefox (44.0.1)Windows
Update for Mozilla Firefox x64 (44.0.1)Windows
Update for Mozilla Firefox (44.0.2)Windows
Update for Mozilla Firefox x64 (44.0.2)Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2.4Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 12.0.3Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 43.0.4Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 43.0.4Windows
Multiple vulnerabilities are fixed in Update for Mozilla Firefox For Mac (44.0)Mac
Multiple vulnerabilities are fixed in Update for Mozilla Firefox For Mac (44.0.1)Mac
Multiple vulnerabilities are fixed in Update for Mozilla Firefox For Mac (44.0.2)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac 38.8Mac
Network Security Service library (USN-2903-1) libnss3_3.21-0ubuntu0.12.04.1_i386.debLinux
Network Security Service library (USN-2903-1) libnss3_3.21-0ubuntu0.12.04.1_amd64.debLinux
Network Security Service library (USN-2903-1) libnss3_3.21-0ubuntu0.14.04.1_i386.debLinux
Network Security Service library (USN-2903-1) libnss3_3.21-0ubuntu0.14.04.1_amd64.debLinux
Network Security Service library (USN-2903-1) libnss3_3.21-0ubuntu0.15.10.1_i386.debLinux
Network Security Service library (USN-2903-1) libnss3_3.21-0ubuntu0.15.10.1_amd64.debLinux
Mozilla Open Source mail and newsgroup client (USN-2973-1) thunderbird_38.8.0+build1-0ubuntu0.12.04.1_i386.debLinux
Mozilla Open Source mail and newsgroup client (USN-2973-1) thunderbird_38.8.0+build1-0ubuntu0.12.04.1_amd64.debLinux
Mozilla Open Source mail and newsgroup client (USN-2973-1) thunderbird_38.8.0+build1-0ubuntu0.14.04.1_i386.debLinux
Mozilla Open Source mail and newsgroup client (USN-2973-1) thunderbird_38.8.0+build1-0ubuntu0.14.04.1_amd64.debLinux
Mozilla Open Source mail and newsgroup client (USN-2973-1) thunderbird_38.8.0+build1-0ubuntu0.15.10.1_i386.debLinux
Mozilla Open Source mail and newsgroup client (USN-2973-1) thunderbird_38.8.0+build1-0ubuntu0.15.10.1_amd64.debLinux
Mozilla Open Source mail and newsgroup client (USN-2973-1) thunderbird_38.8.0+build1-0ubuntu0.16.04.1_i386.debLinux
Mozilla Open Source mail and newsgroup client (USN-2973-1) thunderbird_38.8.0+build1-0ubuntu0.16.04.1_amd64.debLinux
SUSE-SU-2016:0334-1(SUSE Linux Enterprise Desktop 11-SP3 ) MozillaFirefox-38.6.0esr-31.3.x86_64.rpmLinux
SUSE-SU-2016:0334-1(SUSE Linux Enterprise Desktop 11-SP3 ) MozillaFirefox-branding-SLED-38-18.24.x86_64.rpmLinux
SUSE-SU-2016:0334-1(SUSE Linux Enterprise Desktop 11-SP3 ) MozillaFirefox-translations-38.6.0esr-31.3.x86_64.rpmLinux
SUSE-SU-2016:0334-1(SUSE Linux Enterprise Desktop 11-SP3 ) libfreebl3-3.20.2-25.2.x86_64.rpmLinux
SUSE-SU-2016:0334-1(SUSE Linux Enterprise Desktop 11-SP3 ) libfreebl3-32bit-3.20.2-25.2.x86_64.rpmLinux
SUSE-SU-2016:0334-1(SUSE Linux Enterprise Desktop 11-SP3 ) libsoftokn3-3.20.2-25.2.x86_64.rpmLinux
SUSE-SU-2016:0334-1(SUSE Linux Enterprise Desktop 11-SP3 ) libsoftokn3-32bit-3.20.2-25.2.x86_64.rpmLinux
SUSE-SU-2016:0334-1(SUSE Linux Enterprise Desktop 11-SP3 ) mozilla-nss-3.20.2-25.2.x86_64.rpmLinux
SUSE-SU-2016:0334-1(SUSE Linux Enterprise Desktop 11-SP3 ) mozilla-nss-32bit-3.20.2-25.2.x86_64.rpmLinux
SUSE-SU-2016:0334-1(SUSE Linux Enterprise Desktop 11-SP3 ) mozilla-nss-tools-3.20.2-25.2.x86_64.rpmLinux
CVE-2016-1938NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-302195Update for Mozilla Firefox (44.0)
PATCH-302196Update for Mozilla Firefox x64 (44.0)
PATCH-302198Update for Mozilla Firefox x64 (44.0.1)
PATCH-302199Update for Mozilla Firefox (44.0.2)
PATCH-302200Update for Mozilla Firefox x64 (44.0.2)
PATCH-607000Mozilla Firefox For Mac (124.0)
PATCH-607000Mozilla Firefox For Mac (124.0)
PATCH-607000Mozilla Firefox For Mac (124.0)
PATCH-612783Mozilla Firefox For Mac (145.0.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234