#VU2243 Information disclosure in Oracle Solaris - CVE-2016-9074


| Updated: 2017-06-29

Vulnerability identifier: #VU2243

Vulnerability risk: Low

CVSSv4.0: N/A

CVE-ID: CVE-2016-9074

CWE-ID: CWE-310

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Oracle Solaris
Operating systems & Components / Operating system

Vendor: Oracle

Description
Franziskus Kiefer discovered that NSS incorrectly mitigated certain timing side-channel attacks. A remote attacker could possibly use this flaw to recover private keys.

Vulnerable software versions

Oracle Solaris: 11.3


External links
https://www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability