Lucene search

K
suseSuseOPENSUSE-SU-2014:1224-1
HistorySep 28, 2014 - 12:04 p.m.

NSS update to avoid signature forgery (critical)

2014-09-2812:04:18
lists.opensuse.org
22

EPSS

0.038

Percentile

91.9%

NSS is vulnerable to a variant of a signature forgery attack previously
published by Daniel Bleichenbacher. This is due to lenient parsing of
ASN.1 values involved in a signature and could lead to the forging of RSA
certificates.