Lucene search

K
ubuntuUbuntuUSN-2672-1
HistoryJul 09, 2015 - 12:00 a.m.

NSS vulnerabilities

2015-07-0900:00:00
ubuntu.com
46

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.2

Confidence

Low

EPSS

0.003

Percentile

70.7%

Releases

  • Ubuntu 15.04
  • Ubuntu 14.10
  • Ubuntu 14.04 ESM
  • Ubuntu 12.04

Packages

  • nss - Network Security Service library

Details

Karthikeyan Bhargavan discovered that NSS incorrectly handled state
transitions for the TLS state machine. If a remote attacker were able to
perform a machine-in-the-middle attack, this flaw could be exploited to skip
the ServerKeyExchange message and remove the forward-secrecy property.
(CVE-2015-2721)

Watson Ladd discovered that NSS incorrectly handled Elliptical Curve
Cryptography (ECC) multiplication. A remote attacker could possibly use
this issue to spoof ECDSA signatures. (CVE-2015-2730)

As a security improvement, this update modifies NSS behaviour to reject DH
key sizes below 768 bits, preventing a possible downgrade attack.

This update also refreshes the NSS package to version 3.19.2 which includes
the latest CA certificate bundle.

OSVersionArchitecturePackageVersionFilename
Ubuntu15.04noarchlibnss3< 2:3.19.2-0ubuntu15.04.1UNKNOWN
Ubuntu15.04noarchlibnss3-1d< 2:3.19.2-0ubuntu15.04.1UNKNOWN
Ubuntu15.04noarchlibnss3-dbg< 2:3.19.2-0ubuntu15.04.1UNKNOWN
Ubuntu15.04noarchlibnss3-dbgsym< 2:3.19.2-0ubuntu15.04.1UNKNOWN
Ubuntu15.04noarchlibnss3-dev< 2:3.19.2-0ubuntu15.04.1UNKNOWN
Ubuntu15.04noarchlibnss3-nssdb< 2:3.19.2-0ubuntu15.04.1UNKNOWN
Ubuntu15.04noarchlibnss3-tools< 2:3.19.2-0ubuntu15.04.1UNKNOWN
Ubuntu15.04noarchlibnss3-tools-dbgsym< 2:3.19.2-0ubuntu15.04.1UNKNOWN
Ubuntu14.10noarchlibnss3< 2:3.19.2-0ubuntu0.14.10.1UNKNOWN
Ubuntu14.10noarchlibnss3-1d< 2:3.19.2-0ubuntu0.14.10.1UNKNOWN
Rows per page:
1-10 of 291

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.2

Confidence

Low

EPSS

0.003

Percentile

70.7%