CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
Percentile
53.0%
CentOS Errata and Security Advisory CESA-2014:1073
Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Applications built with NSS can support SSLv3, TLS, and other
security standards.
It was found that the implementation of Internationalizing Domain Names in
Applications (IDNA) hostname matching in NSS did not follow the RFC 6125
recommendations. This could lead to certain invalid certificates with
international characters to be accepted as valid. (CVE-2014-1492)
In addition, the nss, nss-util, and nss-softokn packages have been upgraded
to upstream version 3.16.2, which provides a number of bug fixes and
enhancements over the previous versions. (BZ#1124659)
Users of NSS are advised to upgrade to these updated packages, which
correct these issues and add these enhancements. After installing this
update, applications using NSS must be restarted for this update to
take effect.
Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2014-August/082659.html
https://lists.centos.org/pipermail/centos-announce/2014-August/082660.html
https://lists.centos.org/pipermail/centos-announce/2014-August/082661.html
Affected packages:
nss
nss-devel
nss-pkcs11-devel
nss-softokn
nss-softokn-devel
nss-softokn-freebl
nss-softokn-freebl-devel
nss-sysinit
nss-tools
nss-util
nss-util-devel
Upstream details at:
https://access.redhat.com/errata/RHSA-2014:1073
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
CentOS | 7 | i686 | nss-util | < 3.16.2-1.el7_0 | nss-util-3.16.2-1.el7_0.i686.rpm |
CentOS | 7 | x86_64 | nss-util | < 3.16.2-1.el7_0 | nss-util-3.16.2-1.el7_0.x86_64.rpm |
CentOS | 7 | i686 | nss-util-devel | < 3.16.2-1.el7_0 | nss-util-devel-3.16.2-1.el7_0.i686.rpm |
CentOS | 7 | x86_64 | nss-util-devel | < 3.16.2-1.el7_0 | nss-util-devel-3.16.2-1.el7_0.x86_64.rpm |
CentOS | 7 | i686 | nss-softokn | < 3.16.2-1.el7_0 | nss-softokn-3.16.2-1.el7_0.i686.rpm |
CentOS | 7 | x86_64 | nss-softokn | < 3.16.2-1.el7_0 | nss-softokn-3.16.2-1.el7_0.x86_64.rpm |
CentOS | 7 | i686 | nss-softokn-devel | < 3.16.2-1.el7_0 | nss-softokn-devel-3.16.2-1.el7_0.i686.rpm |
CentOS | 7 | x86_64 | nss-softokn-devel | < 3.16.2-1.el7_0 | nss-softokn-devel-3.16.2-1.el7_0.x86_64.rpm |
CentOS | 7 | i686 | nss-softokn-freebl | < 3.16.2-1.el7_0 | nss-softokn-freebl-3.16.2-1.el7_0.i686.rpm |
CentOS | 7 | x86_64 | nss-softokn-freebl | < 3.16.2-1.el7_0 | nss-softokn-freebl-3.16.2-1.el7_0.x86_64.rpm |