It was found that Diffie Hellman Client key exchange handling in NSS, was vulnerable to small subgroup confinement attack[1]. An attacker could use this flaw to recover private keys by confining the client DH key to small subgroup of the desired group. [1] https://en.wikipedia.org/wiki/Small_subgroup_confinement_attack
Acknowledgments: Name: Hubert Kario (Red Hat)
This issue has been addressed in the following products: Red Hat Enterprise Linux 6 Red Hat Enterprise Linux 7 Red Hat Enterprise Linux 5 Via RHSA-2016:2779 https://rhn.redhat.com/errata/RHSA-2016-2779.html