Resource exhaustion in Mozilla NSS and Mozilla Firefox - CVE-2016-1978

 

Resource exhaustion in Mozilla NSS and Mozilla Firefox - CVE-2016-1978

Published: October 20, 2023


Vulnerability identifier: #VU82285
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-1978
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger resource exhaustion and cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption


Affected software

Mozilla NSS
Mozilla Firefox
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server from RHUI
FlashSystem 840 9840-AE1 & 9843-AE1
FlashSystem 900 9840-AE2 and 9843-AE2
SAN Volume Controller and Storwize Family
nss (Red Hat package)
nspr (Red Hat package)

How to mitigate CVE-2016-1978

Install updates from vendor's website.

Mozilla NSS - update to 3.21
Mozilla Firefox - update to 44.0
FlashSystem 840 9840-AE1 & 9843-AE1 - addressed in versions 1.3.0.6, 1.4.5.0
FlashSystem 900 9840-AE2 and 9843-AE2 - addressed in versions 1.3.0.6, 1.4.5.0
nss (Red Hat package) - update to 3.21.0-6.el5_11
nspr (Red Hat package) - update to 4.11.0-1.el5_11
SAN Volume Controller and Storwize Family - addressed in versions 7.5.0.9, 7.6.1.5

External References

Related Security Bulletins