CVE-2016-9074: Infoleak
An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NSS) 3.26.1.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2016-5296
- CVE-2016-5294
- CVE-2016-5297
- CVE-2016-9066
- CVE-2016-5291
- CVE-2016-9074
- CVE-2016-5290
- CVE-2016-5292
- CVE-2016-5293
- CVE-2016-9064
- CVE-2016-9065
- CVE-2016-9067
- CVE-2016-9068
- CVE-2016-9072
- CVE-2016-9075
- CVE-2016-9077
- CVE-2016-5295
- CVE-2016-5298
- CVE-2016-5299
- CVE-2016-9061
- CVE-2016-9062
- CVE-2016-9070
- CVE-2016-9073
- CVE-2016-9076
- CVE-2016-9063
- CVE-2016-9071
- CVE-2016-5289
Frequently Asked Questions
What is the severity of CVE-2016-9074?
The severity of CVE-2016-9074 is medium.
Which software versions are affected by CVE-2016-9074?
CVE-2016-9074 affects Thunderbird versions below 45.5, Firefox ESR versions below 45.5, and Firefox versions below 50.
How can I mitigate the vulnerability in Thunderbird?
To mitigate the vulnerability in Thunderbird, update to version 45.5 or later.
How can I mitigate the vulnerability in Firefox ESR?
To mitigate the vulnerability in Firefox ESR, update to version 45.5 or later.
How can I mitigate the vulnerability in Firefox?
To mitigate the vulnerability in Firefox, update to version 50 or later.
What is the CVE identifier for this vulnerability?
The CVE identifier for this vulnerability is CVE-2016-9074.
Is there any additional information about this vulnerability?
Yes, you can find additional information about this vulnerability in the following references: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1293334), [Mozilla Security Advisory - MFSA2016-93](https://www.mozilla.org/en-US/security/advisories/mfsa2016-93/), [Mozilla Security Advisory - MFSA2016-89](https://www.mozilla.org/en-US/security/advisories/mfsa2016-89/).