Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.68488
Category:Ubuntu Local Security Checks
Title:Ubuntu USN-1007-1 (nss)
Summary:NOSUMMARY
Description:Description:
The remote host is missing an update to nss
announced via advisory USN-1007-1.

Details follow:

Richard Moore discovered that NSS would sometimes incorrectly match an SSL
certificate which had a Common Name that used a wildcard followed by a partial
IP address. While it is very unlikely that a Certificate Authority would issue
such a certificate, if an attacker were able to perform a man-in-the-middle
attack, this flaw could be exploited to view sensitive information.
(CVE-2010-3170)

Nelson Bolyard discovered a weakness in the Diffie-Hellman Ephemeral mode
(DHE) key exchange implementation which allowed servers to use a too small
key length. (CVE-2010-3173)

Solution:
The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 8.04 LTS:
libnss3-1d 3.12.8-0ubuntu0.8.04.1

Ubuntu 9.04:
libnss3-1d 3.12.8-0ubuntu0.9.04.1

Ubuntu 9.10:
libnss3-1d 3.12.8-0ubuntu0.9.10.1

Ubuntu 10.04 LTS:
libnss3-1d 3.12.8-0ubuntu0.10.04.1

Ubuntu 10.10:
libnss3-1d 3.12.8-0ubuntu0.10.10.1

After a standard system update you need to restart any applications that
use NSS, such as Firefox, Thunderbird or Evolution, to make all the
necessary changes. This update also includes updated NSPR packages to work
with the new NSS.

http://www.securityspace.com/smysecure/catid.html?in=USN-1007-1

Risk factor : High

CVSS Score:
7.5

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2010-3170
Debian Security Information: DSA-2123 (Google Search)
http://www.debian.org/security/2010/dsa-2123
http://www.mandriva.com/security/advisories?name=MDVSA-2010:210
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12254
http://www.redhat.com/support/errata/RHSA-2010-0781.html
http://www.redhat.com/support/errata/RHSA-2010-0782.html
http://secunia.com/advisories/41839
http://secunia.com/advisories/42867
SuSE Security Announcement: SUSE-SR:2010:020 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00001.html
http://www.ubuntu.com/usn/USN-1007-1
http://www.vupen.com/english/advisories/2011/0061
Common Vulnerability Exposure (CVE) ID: CVE-2010-3173
http://www.mandriva.com/security/advisories?name=MDVSA-2010:211
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12118
CopyrightCopyright (c) 2010 E-Soft Inc. http://www.securityspace.com

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.