Debian Security Advisory DSA 3336-1 (nss - security update)
Information
Severity
Severity
Family
Family
CVSSv2 Base
CVSSv2 Base
CVSSv2 Vector
CVSSv2 Vector
Solution Type
Solution Type
Created
Created
Modified
Modified
Summary
Several vulnerabilities have been discovered in nss, the Mozilla Network Security Service library. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-2721 Karthikeyan Bhargavan discovered that NSS incorrectly handles state transitions for the TLS state machine. A man-in-the-middle attacker could exploit this flaw to skip the ServerKeyExchange message and remove the forward-secrecy property. CVE-2015-2730 Watson Ladd discovered that NSS does not properly perform Elliptical Curve Cryptography (ECC) multiplication, allowing a remote attacker to potentially spoof ECDSA signatures.
Affected Software
Affected Software
nss on Debian Linux
Detection Method
Detection Method
This check tests the installed software version using the apt package manager.
Solution
Solution
For the oldstable distribution (wheezy), these problems have been fixed in version 2:3.14.5-1+deb7u5. For the stable distribution (jessie), these problems have been fixed in version 2:3.17.2-1.1+deb8u1. For the testing distribution (stretch), these problems have been fixed in version 2:3.19.1-1. For the unstable distribution (sid), these problems have been fixed in version 2:3.19.1-1. We recommend that you upgrade your nss packages.
Common Vulnerabilities and Exposures (CVE)
Scan for free your assets for this vulnerability + 99,568 other vulnerabilities
It is easy and free to get started with Mageni and it can be installed in Windows, macOS and Linux.
Processing. Please wait...
Free for 7-days then $4 USD monthly regardless of how many IPs, scans, users, or deployments you have. No Contracts, Cancel at Anytime and 7-days Money-Back Guarantee.