First published: Tue Nov 15 2016(Updated: )
An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NSS) 3.26.1.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Thunderbird | <45.5 | 45.5 |
<50 | 50 | |
Mozilla Firefox ESR | <45.5 | 45.5 |
Mozilla Firefox | <50.0 | |
Mozilla Firefox ESR | <45.5.0 | |
Mozilla Thunderbird | <45.5.0 | |
Debian Debian Linux | =8.0 | |
debian/firefox-esr | 91.12.0esr-1~deb10u1 115.3.1esr-1~deb10u1 102.15.0esr-1~deb11u1 115.3.1esr-1~deb11u1 102.15.1esr-1~deb12u1 115.3.0esr-1~deb12u1 115.3.0esr-1 | |
debian/nss | 2:3.42.1-1+deb10u5 2:3.42.1-1+deb10u6 2:3.61-1+deb11u3 2:3.87.1-1 2:3.93-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2016-9074 is medium.
CVE-2016-9074 affects Thunderbird versions below 45.5, Firefox ESR versions below 45.5, and Firefox versions below 50.
To mitigate the vulnerability in Thunderbird, update to version 45.5 or later.
To mitigate the vulnerability in Firefox ESR, update to version 45.5 or later.
To mitigate the vulnerability in Firefox, update to version 50 or later.
The CVE identifier for this vulnerability is CVE-2016-9074.
Yes, you can find additional information about this vulnerability in the following references: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1293334), [Mozilla Security Advisory - MFSA2016-93](https://www.mozilla.org/en-US/security/advisories/mfsa2016-93/), [Mozilla Security Advisory - MFSA2016-89](https://www.mozilla.org/en-US/security/advisories/mfsa2016-89/).