| Mozilla Network Security Services (NSS) before 3.15.4, as used in
Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird
before 24.3, SeaMonkey before 2.24, and other products, does not
properly restrict public values in Diffie-Hellman key exchanges, which
makes it easier for remote attackers to bypass cryptographic
protection mechanisms in ticket handling by leveraging use of a
certain value.
|