[USN-4417-2] NSS vulnerability
Severity
Medium
Affected Packages
9
CVEs
1
NSS could be made to expose sensitive information.
USN-4417-1 fixed a vulnerability in NSS. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
Cesar Pereida, Billy Bob Brumley, Yuval Yarom, and Nicola Tuveri discovered
that NSS incorrectly handled RSA key generation. A local attacker could
possibly use this issue to perform a timing attack and recover RSA keys.
Package | Affected Version |
---|---|
pkg:deb/ubuntu/libnss3?distro=trusty | < 3.28.4-0ubuntu0.14.04.5+esm6 |
pkg:deb/ubuntu/libnss3?distro=precise | < 3.28.4-0ubuntu0.12.04.9 |
pkg:deb/ubuntu/libnss3-tools?distro=trusty | < 3.28.4-0ubuntu0.14.04.5+esm6 |
pkg:deb/ubuntu/libnss3-tools?distro=precise | < 3.28.4-0ubuntu0.12.04.9 |
pkg:deb/ubuntu/libnss3-nssdb?distro=trusty | < 3.28.4-0ubuntu0.14.04.5+esm6 |
pkg:deb/ubuntu/libnss3-dev?distro=trusty | < 3.28.4-0ubuntu0.14.04.5+esm6 |
pkg:deb/ubuntu/libnss3-dev?distro=precise | < 3.28.4-0ubuntu0.12.04.9 |
pkg:deb/ubuntu/libnss3-1d?distro=trusty | < 3.28.4-0ubuntu0.14.04.5+esm6 |
pkg:deb/ubuntu/libnss3-1d?distro=precise | < 3.28.4-0ubuntu0.12.04.9 |
- ID
- USN-4417-2
- Severity
- medium
- URL
- https://ubuntu.com/security/notices/USN-4417-2
- Published
-
2020-07-06T19:59:43
(4 years ago) - Modified
-
2020-07-06T19:59:43
(4 years ago) - Other Advisories
-
- ALAS-2021-1522
- ALAS2-2020-1559
- ALPINE:CVE-2020-12402
- ALSA-2020:3280
- DSA-4726-1
- ELSA-2020-3280
- ELSA-2020-4076
- FEDORA-2020-16741ac7ff
- FEDORA-2020-3ef1937475
- GLSA-202007-10
- MFSA-2020-24
- MFSA-2020-29
- openSUSE-SU-2020:0953-1
- openSUSE-SU-2020:0955-1
- openSUSE-SU-2020:0983-1
- openSUSE-SU-2020:1017-1
- RHSA-2020:3280
- RHSA-2020:4076
- SUSE-SU-2020:1839-1
- SUSE-SU-2020:1850-1
- SUSE-SU-2020:1898-1
- SUSE-SU-2020:1899-1
- USN-4417-1
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:deb/ubuntu/libnss3?distro=trusty | ubuntu | libnss3 | < 3.28.4-0ubuntu0.14.04.5+esm6 | trusty | ||
Affected | pkg:deb/ubuntu/libnss3?distro=precise | ubuntu | libnss3 | < 3.28.4-0ubuntu0.12.04.9 | precise | ||
Affected | pkg:deb/ubuntu/libnss3-tools?distro=trusty | ubuntu | libnss3-tools | < 3.28.4-0ubuntu0.14.04.5+esm6 | trusty | ||
Affected | pkg:deb/ubuntu/libnss3-tools?distro=precise | ubuntu | libnss3-tools | < 3.28.4-0ubuntu0.12.04.9 | precise | ||
Affected | pkg:deb/ubuntu/libnss3-nssdb?distro=trusty | ubuntu | libnss3-nssdb | < 3.28.4-0ubuntu0.14.04.5+esm6 | trusty | ||
Affected | pkg:deb/ubuntu/libnss3-dev?distro=trusty | ubuntu | libnss3-dev | < 3.28.4-0ubuntu0.14.04.5+esm6 | trusty | ||
Affected | pkg:deb/ubuntu/libnss3-dev?distro=precise | ubuntu | libnss3-dev | < 3.28.4-0ubuntu0.12.04.9 | precise | ||
Affected | pkg:deb/ubuntu/libnss3-1d?distro=trusty | ubuntu | libnss3-1d | < 3.28.4-0ubuntu0.14.04.5+esm6 | trusty | ||
Affected | pkg:deb/ubuntu/libnss3-1d?distro=precise | ubuntu | libnss3-1d | < 3.28.4-0ubuntu0.12.04.9 | precise |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |