|Category:||Red Hat Local Security Checks|
|Title:||RedHat Update for nss RHSA-2015:1664-01|
|Summary:||The remote host is missing an update for the 'nss'; package(s) announced via the referenced advisory.|
The remote host is missing an update for the 'nss'
package(s) announced via the referenced advisory.
Network Security Services (NSS) is a set of libraries designed to support
cross-platform development of security-enabled client and server
It was found that NSS permitted skipping of the ServerKeyExchange packet
during a handshake involving ECDHE (Elliptic Curve Diffie-Hellman key
Exchange). A remote attacker could use this flaw to bypass the
forward-secrecy of a TLS/SSL connection. (CVE-2015-2721)
A flaw was found in the way NSS verified certain ECDSA (Elliptic Curve
Digital Signature Algorithm) signatures. Under certain conditions, an
attacker could use this flaw to conduct signature forgery attacks.
Red Hat would like to thank the Mozilla project for reporting this issue.
Upstream acknowledges Karthikeyan Bhargavan as the original reporter of
CVE-2015-2721, and Watson Ladd as the original reporter of CVE-2015-2730.
The nss packages have been upgraded to upstream version 3.19.1, which
provides a number of bug fixes and enhancements over the previous version.
All nss users are advised to upgrade to these updated packages, which
correct these issues.
nss on Red Hat Enterprise Linux (v. 5 server)
Please Install the Updated Packages.
Common Vulnerability Exposure (CVE) ID: CVE-2015-2721|
BugTraq ID: 75541
BugTraq ID: 83398
BugTraq ID: 91787
Debian Security Information: DSA-3324 (Google Search)
Debian Security Information: DSA-3336 (Google Search)
RedHat Security Advisories: RHSA-2015:1185
RedHat Security Advisories: RHSA-2015:1664
SuSE Security Announcement: SUSE-SU-2015:1268 (Google Search)
SuSE Security Announcement: SUSE-SU-2015:1269 (Google Search)
SuSE Security Announcement: SUSE-SU-2015:1449 (Google Search)
SuSE Security Announcement: openSUSE-SU-2015:1229 (Google Search)
SuSE Security Announcement: openSUSE-SU-2015:1266 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2015-2730
BugTraq ID: 83399
RedHat Security Advisories: RHSA-2015:1699
|Copyright||Copyright (C) 2015 Greenbone Networks GmbH|
|This is only one of 97459 vulnerability tests in our test suite. Find out more about running a complete security audit.|
To run a free test of this vulnerability against your system, register below.