Red Hat Bugzilla – Bug 1315565
CVE-2016-1978 nss: Use-after-free in NSS during SSL connections in low memory (MFSA 2016-15)
Last modified: 2016-04-25 08:15:12 EDT
Mozilla developer Eric Rescorla reported that a failed allocation during DHE and ECDHE handshakes would lead to a use-after-free vulnerability. External Reference: https://www.mozilla.org/security/announce/2016/mfsa2016-15.html
Acknowledgments: Name: the Mozilla project Upstream: Eric Rescorla
Created nss tracking bugs for this issue: Affects: fedora-all [bug 1316003]
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Via RHSA-2016:0591 https://rhn.redhat.com/errata/RHSA-2016-0591.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2016:0685 https://rhn.redhat.com/errata/RHSA-2016-0685.html
This issue has been addressed in the following products: Red Hat Enterprise Linux 5 Via RHSA-2016:0684 https://rhn.redhat.com/errata/RHSA-2016-0684.html