Security Advisory

CVE-2016-5285

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-11-15 15:44:05
Last updated 2024-08-06 00:53:48
Assigner mozilla
State PUBLISHED

Description

A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.