[ALAS-2014-424] Amazon Linux AMI 2014.03 - ALAS-2014-424: important priority package update for nss

Severity Important
Affected Packages 12
CVEs 1

Package updates are available for Amazon Linux AMI that fix the following vulnerabilities:
CVE-2014-1568:
A flaw was found in the way NSS parsed ASN.1 (Abstract Syntax Notation One) input from certain RSA signatures. A remote attacker could use this flaw to forge RSA certificates by providing a specially crafted signature to an application using NSS.
1145429:
CVE-2014-1568 nss: RSA PKCS#1 signature verification forgery flaw (MFSA 2014-73)

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/amazonlinux/nss?arch=x86_64&distro=amazonlinux-1 amazonlinux nss < 3.16.2-7.49.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/nss?arch=i686&distro=amazonlinux-1 amazonlinux nss < 3.16.2-7.49.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/nss-tools?arch=x86_64&distro=amazonlinux-1 amazonlinux nss-tools < 3.16.2-7.49.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/nss-tools?arch=i686&distro=amazonlinux-1 amazonlinux nss-tools < 3.16.2-7.49.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/nss-sysinit?arch=x86_64&distro=amazonlinux-1 amazonlinux nss-sysinit < 3.16.2-7.49.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/nss-sysinit?arch=i686&distro=amazonlinux-1 amazonlinux nss-sysinit < 3.16.2-7.49.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/nss-pkcs11-devel?arch=x86_64&distro=amazonlinux-1 amazonlinux nss-pkcs11-devel < 3.16.2-7.49.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/nss-pkcs11-devel?arch=i686&distro=amazonlinux-1 amazonlinux nss-pkcs11-devel < 3.16.2-7.49.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/nss-devel?arch=x86_64&distro=amazonlinux-1 amazonlinux nss-devel < 3.16.2-7.49.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/nss-devel?arch=i686&distro=amazonlinux-1 amazonlinux nss-devel < 3.16.2-7.49.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/nss-debuginfo?arch=x86_64&distro=amazonlinux-1 amazonlinux nss-debuginfo < 3.16.2-7.49.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/nss-debuginfo?arch=i686&distro=amazonlinux-1 amazonlinux nss-debuginfo < 3.16.2-7.49.amzn1 amazonlinux-1 i686
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...