CVE-2016-9574

Description

nss before version 3.30 is vulnerable to a remote denial of service during the session handshake when using SessionTicket extension and ECDHE-ECDSA.

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.184

Associated Vulnerability

VulnerabilityOS Platform
SUSE-SU-2017:1175-1(SUSE Linux Enterprise Server 11-SP4 ) mozilla-nspr-4.13.1-32.1.x86_64.rpmLinux
SUSE-SU-2017:1175-1(SUSE Linux Enterprise Server 11-SP4 ) mozilla-nspr-32bit-4.13.1-32.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) MozillaFirefox-45.9.0esr-105.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) MozillaFirefox-debuginfo-45.9.0esr-105.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) MozillaFirefox-debugsource-45.9.0esr-105.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) MozillaFirefox-translations-45.9.0esr-105.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) java-1_8_0-openjdk-1.8.0.121-23.4.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) java-1_8_0-openjdk-debuginfo-1.8.0.121-23.4.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) java-1_8_0-openjdk-debugsource-1.8.0.121-23.4.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Server 12-SP1 ) java-1_8_0-openjdk-demo-1.8.0.121-23.4.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Server 12-SP1 ) java-1_8_0-openjdk-demo-debuginfo-1.8.0.121-23.4.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Server 12-SP1 ) java-1_8_0-openjdk-devel-1.8.0.121-23.4.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) java-1_8_0-openjdk-headless-1.8.0.121-23.4.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) java-1_8_0-openjdk-headless-debuginfo-1.8.0.121-23.4.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) libfreebl3-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) libfreebl3-32bit-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) libfreebl3-debuginfo-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) libfreebl3-debuginfo-32bit-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Server 12-SP1 ) libfreebl3-hmac-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Server 12-SP1 ) libfreebl3-hmac-32bit-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) libsoftokn3-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) libsoftokn3-32bit-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) libsoftokn3-debuginfo-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) libsoftokn3-debuginfo-32bit-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Server 12-SP1 ) libsoftokn3-hmac-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Server 12-SP1 ) libsoftokn3-hmac-32bit-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) mozilla-nspr-4.13.1-18.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) mozilla-nspr-32bit-4.13.1-18.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) mozilla-nspr-debuginfo-4.13.1-18.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) mozilla-nspr-debuginfo-32bit-4.13.1-18.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) mozilla-nspr-debugsource-4.13.1-18.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) mozilla-nss-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) mozilla-nss-32bit-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) mozilla-nss-certs-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) mozilla-nss-certs-32bit-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) mozilla-nss-certs-debuginfo-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) mozilla-nss-certs-debuginfo-32bit-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) mozilla-nss-debuginfo-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) mozilla-nss-debuginfo-32bit-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) mozilla-nss-debugsource-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) mozilla-nss-sysinit-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) mozilla-nss-sysinit-32bit-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) mozilla-nss-sysinit-debuginfo-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) mozilla-nss-sysinit-debuginfo-32bit-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) mozilla-nss-tools-3.29.5-57.1.x86_64.rpmLinux
SUSE-SU-2017:1248-1(SUSE Linux Enterprise Desktop 12-SP1 ) mozilla-nss-tools-debuginfo-3.29.5-57.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234