Lucene search

K
ubuntuUbuntuUSN-5168-4
HistoryDec 07, 2021 - 12:00 a.m.

NSS regression

2021-12-0700:00:00
ubuntu.com
71
nss
regression
fix
ubuntu
16.04
14.04
network security service
ssl
denial of service

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

10

Confidence

High

EPSS

0.008

Percentile

81.4%

Releases

  • Ubuntu 16.04 ESM
  • Ubuntu 14.04 ESM

Packages

  • nss - Network Security Service library

Details

USN-5168-3 fixed a vulnerability in NSS. Unfortunately that update introduced
a regression that could break SSL connections. This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

Tavis Ormandy discovered that NSS incorrectly handled verifying DSA/RSA-PSS
signatures. A remote attacker could use this issue to cause NSS to crash,
resulting in a denial of service, or possibly execute arbitrary code.

OSVersionArchitecturePackageVersionFilename
Ubuntu16.04noarchlibnss3< 2:3.28.4-0ubuntu0.16.04.14+esm2UNKNOWN
Ubuntu16.04noarchlibnss3< 2:3.28.4-0ubuntu0.16.04.14UNKNOWN
Ubuntu16.04noarchlibnss3-1d< 2:3.28.4-0ubuntu0.16.04.14UNKNOWN
Ubuntu16.04noarchlibnss3-dbg< 2:3.28.4-0ubuntu0.16.04.14UNKNOWN
Ubuntu16.04noarchlibnss3-dbgsym< 2:3.28.4-0ubuntu0.16.04.14UNKNOWN
Ubuntu16.04noarchlibnss3-dev< 2:3.28.4-0ubuntu0.16.04.14UNKNOWN
Ubuntu16.04noarchlibnss3-nssdb< 2:3.28.4-0ubuntu0.16.04.14UNKNOWN
Ubuntu16.04noarchlibnss3-tools< 2:3.28.4-0ubuntu0.16.04.14UNKNOWN
Ubuntu16.04noarchlibnss3-tools-dbgsym< 2:3.28.4-0ubuntu0.16.04.14UNKNOWN
Ubuntu14.04noarchlibnss3< 2:3.28.4-0ubuntu0.14.04.5+esm10UNKNOWN
Rows per page:
1-10 of 171

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

10

Confidence

High

EPSS

0.008

Percentile

81.4%