Vulnerability identifier: #VU2243
Vulnerability risk: Low
CVSSv4.0: N/A
CVE-ID:
CWE-ID:
CWE-310
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Oracle Solaris
Operating systems & Components /
Operating system
Vendor: Oracle
Description
Franziskus Kiefer discovered that NSS incorrectly mitigated certain timing side-channel attacks. A remote attacker could possibly use this flaw to recover private keys.
Vulnerable software versions
Oracle Solaris: 11.3
External links
https://www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.html
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.