A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.

Project Subscriptions

Vendors Products
Aura Application Enablement Services Subscribe
Aura Application Server 5300 Subscribe
Aura Communication Manager Subscribe
Aura Communication Manager Messagint Subscribe
Aura Conferencing Subscribe
Aura Experience Portal Subscribe
Aura Messaging Subscribe
Aura Session Manager Subscribe
Aura System Manager Subscribe
Aura System Platform Subscribe
Aura System Platform Firmware Subscribe
Aura Utility Services Subscribe
Breeze Platform Subscribe
Call Management System Subscribe
Cs1000e Subscribe
Cs1000e\/cs1000m Signaling Server Subscribe
Cs1000e\/cs1000m Signaling Server Firmware Subscribe
Cs1000e Firmware Subscribe
Cs1000m Subscribe
Cs1000m Firmware Subscribe
Ip Office Subscribe
Meeting Exchange Subscribe
Message Networking Subscribe
One-x Client Enablement Services Subscribe
Proactive Contact Subscribe
Session Border Controller For Enterprise Subscribe
Session Border Controller For Enterprise Firmware Subscribe
Debian Linux Subscribe
Mozilla Subscribe
Enterprise Linux Subscribe
Linux Enterprise Server Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2016-6236 A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
Ubuntu USN Ubuntu USN USN-3163-1 NSS vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2024-08-06T00:53:48.923Z

Reserved: 2016-06-03T00:00:00.000Z

Link: CVE-2016-5285

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-11-15T16:15:10.110

Modified: 2024-11-21T02:53:59.990

Link: CVE-2016-5285

cve-icon Redhat

Severity : Moderate

Publid Date: 2016-11-16T00:00:00Z

Links: CVE-2016-5285 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses