Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:
Category:Red Hat Local Security Checks
Title:RedHat Update for nss and nspr RHSA-2014:1246-01
Summary:The remote host is missing an update for the 'nss and nspr'; package(s) announced via the referenced advisory.
The remote host is missing an update for the 'nss and nspr'
package(s) announced via the referenced advisory.

Vulnerability Insight:
Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server

A flaw was found in the way TLS False Start was implemented in NSS.
An attacker could use this flaw to potentially return unencrypted
information from the server. (CVE-2013-1740)

A race condition was found in the way NSS implemented session ticket
handling as specified by RFC 5077. An attacker could use this flaw to crash
an application using NSS or, in rare cases, execute arbitrary code with the
privileges of the user running that application. (CVE-2014-1490)

It was found that NSS accepted weak Diffie-Hellman Key exchange (DHKE)
parameters. This could possibly lead to weak encryption being used in
communication between the client and the server. (CVE-2014-1491)

An out-of-bounds write flaw was found in NSPR. A remote attacker could
potentially use this flaw to crash an application using NSPR or, possibly,
execute arbitrary code with the privileges of the user running that
application. This NSPR flaw was not exposed to web content in any shipped
version of Firefox. (CVE-2014-1545)

It was found that the implementation of Internationalizing Domain Names in
Applications (IDNA) hostname matching in NSS did not follow the RFC 6125
recommendations. This could lead to certain invalid certificates with
international characters to be accepted as valid. (CVE-2014-1492)

Red Hat would like to thank the Mozilla project for reporting the
CVE-2014-1490, CVE-2014-1491, and CVE-2014-1545 issues. Upstream
acknowledges Brian Smith as the original reporter of CVE-2014-1490, Antoine
Delignat-Lavaud and Karthikeyan Bhargavan as the original reporters of
CVE-2014-1491, and Abhishek Arya as the original reporter of CVE-2014-1545.

The nss and nspr packages have been upgraded to upstream version 3.16.1 and
4.10.6 respectively, which provide a number of bug fixes and enhancements
over the previous versions. (BZ#1110857, BZ#1110860)

This update also fixes the following bugs:

* Previously, when the output.log file was not present on the system, the
shell in the Network Security Services (NSS) specification handled test
failures incorrectly as false positive test results. Consequently, certain
utilities, such as 'grep', could not handle failures properly. This update
improves error detection in the specification file, and 'grep' and other
utilities now handle missing files or crashes as intended. (BZ#1035281)

* Prior to this update, a subordinate Certificate Authority (CA) of the
ANSSI agency incorrectly issued an intermediate c ...

Description truncated, please see the referenced URL(s) for more information.

Affected Software/OS:
nss and nspr on Red Hat Enterprise Linux (v. 5 server)

Please Install the Updated Packages.

CVSS Score:

CVSS Vector:

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2013-1740
BugTraq ID: 64944
Bugtraq: 20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities (Google Search)
SuSE Security Announcement: openSUSE-SU-2014:0212 (Google Search)
SuSE Security Announcement: openSUSE-SU-2014:0213 (Google Search)
XForce ISS Database: mozilla-nss-cve20131740-info-disc(90394)
Common Vulnerability Exposure (CVE) ID: CVE-2014-1490
BugTraq ID: 65335
Debian Security Information: DSA-2858 (Google Search)
SuSE Security Announcement: SUSE-SU-2014:0248 (Google Search)
SuSE Security Announcement: openSUSE-SU-2014:0419 (Google Search)
XForce ISS Database: mozilla-nss-cve20141490-code-exec(90885)
Common Vulnerability Exposure (CVE) ID: CVE-2014-1491
BugTraq ID: 65332
Debian Security Information: DSA-2994 (Google Search)
XForce ISS Database: firefox-nss-cve20141491-unspecified(90886)
Common Vulnerability Exposure (CVE) ID: CVE-2014-1492
BugTraq ID: 66356
SuSE Security Announcement: SUSE-SU-2014:0665 (Google Search)
SuSE Security Announcement: SUSE-SU-2014:0727 (Google Search)
SuSE Security Announcement: openSUSE-SU-2014:0599 (Google Search)
SuSE Security Announcement: openSUSE-SU-2014:0629 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2014-1545
BugTraq ID: 67975
Debian Security Information: DSA-2955 (Google Search)
Debian Security Information: DSA-2960 (Google Search)
Debian Security Information: DSA-2962 (Google Search)
SuSE Security Announcement: SUSE-SU-2014:0824 (Google Search)
SuSE Security Announcement: openSUSE-SU-2014:0797 (Google Search)
SuSE Security Announcement: openSUSE-SU-2014:0819 (Google Search)
SuSE Security Announcement: openSUSE-SU-2014:0855 (Google Search)
SuSE Security Announcement: openSUSE-SU-2014:0858 (Google Search)
CopyrightCopyright (C) 2014 Greenbone Networks GmbH

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

© 1998-2021 E-Soft Inc. All rights reserved.