Medium severity5.9NVD Advisory· Published Jan 9, 2016· Updated Jun 17, 2026
CVE-2015-7575
CVE-2015-7575
Description
Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
79cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*+ 12 more
- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*range: <=43.0.1
- cpe:2.3:a:mozilla:firefox:38.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:38.5.1:*:*:*:*:*:*:*
- (no CPE)range: <43.0.2
cpe:2.3:a:mozilla:network_security_services:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mozilla:network_security_services:*:*:*:*:*:*:*:*range: <=3.20.1
- (no CPE)range: <3.20.2
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*
- osv-coords58 versionspkg:rpm/opensuse/bouncycastle&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/java-1_7_0-openjdk&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/java-1_8_0-openjdk&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/mbedtls-2&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/mbedtls-3&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/mbedtls&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/mozilla-nss&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Tumbleweedpkg:rpm/suse/java-1_6_0-ibm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2012pkg:rpm/suse/java-1_6_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP2-LTSSpkg:rpm/suse/java-1_6_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-LTSSpkg:rpm/suse/java-1_7_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP2-LTSSpkg:rpm/suse/java-1_7_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-LTSSpkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP3pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP4pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%2012pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012pkg:rpm/suse/java-1_7_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/java-1_7_1-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/java-1_7_1-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2012pkg:rpm/suse/java-1_7_1-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/java-1_7_1-ibm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/java-1_7_1-ibm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012pkg:rpm/suse/java-1_7_1-ibm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/java-1_7_1-ibm&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/java-1_7_1-ibm&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012pkg:rpm/suse/java-1_7_1-ibm&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/java-1_8_0-ibm&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1pkg:rpm/suse/java-1_8_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/java-1_8_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/java-1_8_0-openjdk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/MozillaFirefox-branding-SLED&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP2-LTSSpkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP2-LTSSpkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP3pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP4pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP2-LTSSpkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATApkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%2012pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP3pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP3pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012pkg:rpm/suse/mozilla-nss&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1
< 1.54-1.2+ 57 more
- (no CPE)range: < 1.54-1.2
- (no CPE)range: < 128.5.1-1.1
- (no CPE)range: < 1.7.0.121-1.1
- (no CPE)range: < 1.8.0.111-1.1
- (no CPE)range: < 2.28.3-1.1
- (no CPE)range: < 3.6.6-1.1
- (no CPE)range: < 2.4.0-1.2
- (no CPE)range: < 50.1.0-1.1
- (no CPE)range: < 3.26.2-1.1
- (no CPE)range: < 45.5.1-1.1
- (no CPE)range: < 1.6.0_sr16.20-30.1
- (no CPE)range: < 1.6.0_sr16.20-49.1
- (no CPE)range: < 1.6.0_sr16.20-51.1
- (no CPE)range: < 1.7.0_sr9.30-45.1
- (no CPE)range: < 1.7.0_sr9.30-47.1
- (no CPE)range: < 1.7.0.95-0.17.2
- (no CPE)range: < 1.7.0.95-0.17.2
- (no CPE)range: < 1.7.0.95-24.2
- (no CPE)range: < 1.7.0.95-24.2
- (no CPE)range: < 1.7.0.95-24.2
- (no CPE)range: < 1.7.0.95-24.2
- (no CPE)range: < 1.7.0.95-24.2
- (no CPE)range: < 1.7.0.95-24.2
- (no CPE)range: < 1.7.1_sr3.30-9.1
- (no CPE)range: < 1.7.1_sr3.30-21.1
- (no CPE)range: < 1.7.1_sr3.30-21.1
- (no CPE)range: < 1.7.1_sr3.30-9.1
- (no CPE)range: < 1.7.1_sr3.30-21.1
- (no CPE)range: < 1.7.1_sr3.30-21.1
- (no CPE)range: < 1.7.1_sr3.30-9.1
- (no CPE)range: < 1.7.1_sr3.30-21.1
- (no CPE)range: < 1.7.1_sr3.30-21.1
- (no CPE)range: < 1.8.0_sr2.10-7.1
- (no CPE)range: < 1.8.0_sr2.10-7.1
- (no CPE)range: < 1.8.0_sr2.10-7.1
- (no CPE)range: < 1.8.0.72-3.2
- (no CPE)range: < 1.8.0.72-3.2
- (no CPE)range: < 1.8.0.72-3.2
- (no CPE)range: < 38-15.58
- (no CPE)range: < 38.6.1esr-33.1
- (no CPE)range: < 3.19.2.2-22.1
- (no CPE)range: < 3.19.2.2-22.1
- (no CPE)range: < 3.19.2.2-32.1
- (no CPE)range: < 3.19.2.2-32.1
- (no CPE)range: < 3.20.2-17.5
- (no CPE)range: < 3.19.2.2-22.1
- (no CPE)range: < 3.19.2.2-22.1
- (no CPE)range: < 3.19.2.2-22.1
- (no CPE)range: < 3.19.2.2-32.1
- (no CPE)range: < 3.19.2.2-32.1
- (no CPE)range: < 3.19.2.2-22.1
- (no CPE)range: < 3.19.2.2-22.1
- (no CPE)range: < 3.19.2.2-32.1
- (no CPE)range: < 3.19.2.2-32.1
- (no CPE)range: < 3.19.2.2-22.1
- (no CPE)range: < 3.19.2.2-22.1
- (no CPE)range: < 3.19.2.2-32.1
- (no CPE)range: < 3.19.2.2-32.1
Patches
Vulnerability mechanics
References
52- lists.opensuse.org/opensuse-updates/2016-02/msg00007.htmlnvdThird Party Advisory
- lists.opensuse.org/opensuse-updates/2016-02/msg00008.htmlnvdThird Party Advisory
- www.mozilla.org/security/announce/2015/mfsa2015-150.htmlnvdVendor Advisory
- www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlnvdThird Party Advisory
- www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlnvdThird Party Advisory
- www.oracle.com/technetwork/topics/security/cpujan2016-2367955.htmlnvdVendor Advisory
- www.securityfocus.com/bid/91787nvdThird Party AdvisoryVDB Entry
- www.ubuntu.com/usn/USN-2884-1nvdThird Party Advisory
- developer.mozilla.org/docs/Mozilla/Projects/NSS/NSS_3.20.2_release_notesnvdVendor Advisory
- bugzilla.mozilla.org/show_bug.cginvdIssue Tracking
- lists.opensuse.org/opensuse-security-announce/2016-01/msg00038.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-01/msg00041.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-01/msg00042.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-01/msg00043.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-01/msg00044.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-01/msg00045.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-01/msg00047.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-01/msg00048.htmlnvd
- lists.opensuse.org/opensuse-updates/2015-12/msg00139.htmlnvd
- lists.opensuse.org/opensuse-updates/2016-01/msg00005.htmlnvd
- lists.opensuse.org/opensuse-updates/2016-01/msg00058.htmlnvd
- lists.opensuse.org/opensuse-updates/2016-01/msg00059.htmlnvd
- lists.opensuse.org/opensuse-updates/2016-02/msg00101.htmlnvd
- lists.opensuse.org/opensuse-updates/2016-02/msg00166.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0049.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0050.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0053.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0054.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0055.htmlnvd
- rhn.redhat.com/errata/RHSA-2016-0056.htmlnvd
- www.debian.org/security/2016/dsa-3436nvd
- www.debian.org/security/2016/dsa-3437nvd
- www.debian.org/security/2016/dsa-3457nvd
- www.debian.org/security/2016/dsa-3458nvd
- www.debian.org/security/2016/dsa-3465nvd
- www.debian.org/security/2016/dsa-3491nvd
- www.debian.org/security/2016/dsa-3688nvd
- www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlnvd
- www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlnvd
- www.securityfocus.com/bid/79684nvd
- www.securitytracker.com/id/1034541nvd
- www.securitytracker.com/id/1036467nvd
- www.ubuntu.com/usn/USN-2863-1nvd
- www.ubuntu.com/usn/USN-2864-1nvd
- www.ubuntu.com/usn/USN-2865-1nvd
- www.ubuntu.com/usn/USN-2866-1nvd
- www.ubuntu.com/usn/USN-2904-1nvd
- access.redhat.com/errata/RHSA-2016:1430nvd
- security.gentoo.org/glsa/201701-46nvd
- security.gentoo.org/glsa/201706-18nvd
- security.gentoo.org/glsa/201801-15nvd
- security.netapp.com/advisory/ntap-20160225-0001/nvd
News mentions
0No linked articles in our index yet.