First published: Sun Jan 31 2016(Updated: )
Mozilla Firefox could provide weaker than expected security, caused by the creation of incorrect calculations in certain cases by the Network Security Services (NSS) mp_div() and mp_exptmod() functions. An attacker could exploit this vulnerability to create cryptographic weaknesses.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | <=12.0.0-12.0.3 | |
IBM Cognos Analytics | <=11.2.0-11.2.4 FP4 | |
openSUSE | =42.1 | |
openSUSE | =13.1 | |
openSUSE | =13.2 | |
Mozilla Network Security Services (NSS) | <=3.20.1 | |
Mozilla Firefox | <=43.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1938 has been classified with a moderate severity level due to the potential for creating cryptographic weaknesses.
To fix CVE-2016-1938, ensure that you apply the latest patches provided by your affected software vendor.
CVE-2016-1938 affects various versions of Mozilla Firefox and Network Security Services (NSS), along with IBM Cognos Analytics.
An attacker can exploit CVE-2016-1938 to create weak cryptographic operations, potentially compromising secure communications.
CVE-2016-1938 affects Mozilla Firefox up to version 43.0.4.