Red Hat Bugzilla – Bug 1383883
CVE-2016-5285 nss: Missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime causes server crash
Last modified: 2017-03-16 11:25:28 EDT
A flaw was found in the way a NSS server could be crashed remotely by a client sending an invalid DH key.
Upstream commit: https://hg.mozilla.org/projects/nss/rev/45c047d18ac4
*** Bug 1380235 has been marked as a duplicate of this bug. ***
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 7 Red Hat Enterprise Linux 5 Via RHSA-2016:2779 https://rhn.redhat.com/errata/RHSA-2016-2779.html
Created nss tracking bugs for this issue: Affects: fedora-all [bug 1395535]
*** Bug 1374803 has been marked as a duplicate of this bug. ***