[ALAS-2023-1736] Amazon Linux AMI 2014.03 - ALAS-2023-1736: important priority package update for nss
Severity
Important
Affected Packages
12
CVEs
1
Package updates are available for Amazon Linux AMI that fix the following vulnerabilities:
CVE-2023-0767:
firefox-esr , thunderbird and nss only are affected by this package.
- ID
- ALAS-2023-1736
- Severity
- important
- URL
- https://alas.aws.amazon.com/ALAS-2023-1736.html
- Published
-
2023-04-27T16:19:00
(17 months ago) - Modified
-
2023-05-03T18:49:00
(16 months ago) - Rights
- Amazon Linux Security Team
- Other Advisories
-
- ALAS2-2023-1983
- ALAS2-2023-1992
- ALPINE:CVE-2023-0767
- ALSA-2023:0808
- ALSA-2023:0810
- ALSA-2023:0821
- ALSA-2023:0824
- ALSA-2023:1252
- ALSA-2023:1368
- DSA-5350-1
- DSA-5353-1
- DSA-5355-1
- ELSA-2023-0808
- ELSA-2023-0810
- ELSA-2023-0812
- ELSA-2023-0817
- ELSA-2023-0821
- ELSA-2023-0824
- ELSA-2023-12238
- ELSA-2023-1252
- ELSA-2023-1332
- ELSA-2023-1368
- GLSA-202305-35
- GLSA-202305-36
- MFSA-2023-05
- MFSA-2023-06
- MFSA-2023-07
- RHSA-2023:1252
- RHSA-2023:1332
- RHSA-2023:1368
- RLSA-2023:0808
- RLSA-2023:0810
- RLSA-2023:0821
- RLSA-2023:0824
- RLSA-2023:1252
- RLSA-2023:1368
- SSA:2023-045-01
- SSA:2023-047-01
- SUSE-SU-2023:0434-1
- SUSE-SU-2023:0443-1
- SUSE-SU-2023:0461-1
- SUSE-SU-2023:0466-1
- SUSE-SU-2023:0468-1
- SUSE-SU-2023:0469-1
- SUSE-SU-2023:0599-1
- USN-5880-1
- USN-5892-1
- USN-5892-2
- USN-5943-1
Source | # ID | Name | URL |
---|---|---|---|
CVE | CVE-2023-0767 | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0767 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/amazonlinux/nss?arch=x86_64&distro=amazonlinux-1 | amazonlinux | nss | < 3.53.1-7.88.amzn1 | amazonlinux-1 | x86_64 | |
Affected | pkg:rpm/amazonlinux/nss?arch=i686&distro=amazonlinux-1 | amazonlinux | nss | < 3.53.1-7.88.amzn1 | amazonlinux-1 | i686 | |
Affected | pkg:rpm/amazonlinux/nss-tools?arch=x86_64&distro=amazonlinux-1 | amazonlinux | nss-tools | < 3.53.1-7.88.amzn1 | amazonlinux-1 | x86_64 | |
Affected | pkg:rpm/amazonlinux/nss-tools?arch=i686&distro=amazonlinux-1 | amazonlinux | nss-tools | < 3.53.1-7.88.amzn1 | amazonlinux-1 | i686 | |
Affected | pkg:rpm/amazonlinux/nss-sysinit?arch=x86_64&distro=amazonlinux-1 | amazonlinux | nss-sysinit | < 3.53.1-7.88.amzn1 | amazonlinux-1 | x86_64 | |
Affected | pkg:rpm/amazonlinux/nss-sysinit?arch=i686&distro=amazonlinux-1 | amazonlinux | nss-sysinit | < 3.53.1-7.88.amzn1 | amazonlinux-1 | i686 | |
Affected | pkg:rpm/amazonlinux/nss-pkcs11-devel?arch=x86_64&distro=amazonlinux-1 | amazonlinux | nss-pkcs11-devel | < 3.53.1-7.88.amzn1 | amazonlinux-1 | x86_64 | |
Affected | pkg:rpm/amazonlinux/nss-pkcs11-devel?arch=i686&distro=amazonlinux-1 | amazonlinux | nss-pkcs11-devel | < 3.53.1-7.88.amzn1 | amazonlinux-1 | i686 | |
Affected | pkg:rpm/amazonlinux/nss-devel?arch=x86_64&distro=amazonlinux-1 | amazonlinux | nss-devel | < 3.53.1-7.88.amzn1 | amazonlinux-1 | x86_64 | |
Affected | pkg:rpm/amazonlinux/nss-devel?arch=i686&distro=amazonlinux-1 | amazonlinux | nss-devel | < 3.53.1-7.88.amzn1 | amazonlinux-1 | i686 | |
Affected | pkg:rpm/amazonlinux/nss-debuginfo?arch=x86_64&distro=amazonlinux-1 | amazonlinux | nss-debuginfo | < 3.53.1-7.88.amzn1 | amazonlinux-1 | x86_64 | |
Affected | pkg:rpm/amazonlinux/nss-debuginfo?arch=i686&distro=amazonlinux-1 | amazonlinux | nss-debuginfo | < 3.53.1-7.88.amzn1 | amazonlinux-1 | i686 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |