CVE-2016-9574 REJECTED

nss before version 3.30 is vulnerable to a remote denial of service during the session handshake when using SessionTicket extension and ECDHE-ECDSA.

EPSS 0.18% · 40.0th percentile

Risk Scores

EPSS Score
0.18%
40.0th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSnss0, 2:3.19.2-1ubuntu1, 2:3.19.2.1-0ubuntu1
Ubuntu:14.04:LTSnss2:3.15.4-1ubuntu3, 2:3.15.4-1ubuntu4, 2:3.15.4-1ubuntu5

Timeline

References

Open in Interactive Console →