ubuntu · CVE-2016-1978

Quick triage

Priority: medium Published: 2016-03-13 00:00:00 UTC Updated: 2025-08-25 21:56:11 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2016-1978 medium priority: Ubuntu including 3 source packages (firefox, nss, thunderbird), 21 status rows across 7 suites (precise, trusty, upstream, wily, xenial, yakkety, zesty): released 15, not-affected 6.

Description:

Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact by making an SSL (1) DHE or (2) ECDHE handshake at a time of high memory consumption.

cvelogic Threat Intelligence