[USN-2864-1] NSS vulnerability

Severity Medium
Affected Packages 5
CVEs 1

NSS could be made to expose sensitive information over the network.

Karthikeyan Bhargavan and Gaetan Leurent discovered that NSS incorrectly
allowed MD5 to be used for TLS 1.2 connections. If a remote attacker were
able to perform a machine-in-the-middle attack, this flaw could be exploited to
view sensitive information.

Package Affected Version
pkg:deb/ubuntu/libnss3?distro=trusty < 3.19.2.1-0ubuntu0.14.04.2
pkg:deb/ubuntu/libnss3-tools?distro=trusty < 3.19.2.1-0ubuntu0.14.04.2
pkg:deb/ubuntu/libnss3-nssdb?distro=trusty < 3.19.2.1-0ubuntu0.14.04.2
pkg:deb/ubuntu/libnss3-dev?distro=trusty < 3.19.2.1-0ubuntu0.14.04.2
pkg:deb/ubuntu/libnss3-1d?distro=trusty < 3.19.2.1-0ubuntu0.14.04.2
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/libnss3?distro=trusty ubuntu libnss3 < 3.19.2.1-0ubuntu0.14.04.2 trusty
Affected pkg:deb/ubuntu/libnss3-tools?distro=trusty ubuntu libnss3-tools < 3.19.2.1-0ubuntu0.14.04.2 trusty
Affected pkg:deb/ubuntu/libnss3-nssdb?distro=trusty ubuntu libnss3-nssdb < 3.19.2.1-0ubuntu0.14.04.2 trusty
Affected pkg:deb/ubuntu/libnss3-dev?distro=trusty ubuntu libnss3-dev < 3.19.2.1-0ubuntu0.14.04.2 trusty
Affected pkg:deb/ubuntu/libnss3-1d?distro=trusty ubuntu libnss3-1d < 3.19.2.1-0ubuntu0.14.04.2 trusty
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...