First published: Wed Jan 15 2014(Updated: )
A security issue has been reported in NSS, which can be exploited by a malicious user to disclose certain information. The issue arises due to an error within the "ssl_Do1stHandshake()" function in lib/ssl/sslsecur.c, which can be exploited to potentially return unencrypted and unauthenticated data from PR_Recv. Successful exploitation requires false start to be enabled. The issue is said to be fixed in NSS 3.15.4. References: <a href="https://bugs.gentoo.org/show_bug.cgi?id=498172">https://bugs.gentoo.org/show_bug.cgi?id=498172</a> <a href="https://developer.mozilla.org/en-US/docs/NSS/NSS_3.15.4_release_notes">https://developer.mozilla.org/en-US/docs/NSS/NSS_3.15.4_release_notes</a> Upstream bug: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=919877">https://bugzilla.mozilla.org/show_bug.cgi?id=919877</a> Patch: <a href="https://bugzilla.mozilla.org/attachment.cgi?id=825813">https://bugzilla.mozilla.org/attachment.cgi?id=825813</a>
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Network Security Services | <=3.15.3 | |
Mozilla Network Security Services | =3.2 | |
Mozilla Network Security Services | =3.2.1 | |
Mozilla Network Security Services | =3.3 | |
Mozilla Network Security Services | =3.3.1 | |
Mozilla Network Security Services | =3.3.2 | |
Mozilla Network Security Services | =3.4 | |
Mozilla Network Security Services | =3.4.1 | |
Mozilla Network Security Services | =3.4.2 | |
Mozilla Network Security Services | =3.5 | |
Mozilla Network Security Services | =3.6 | |
Mozilla Network Security Services | =3.6.1 | |
Mozilla Network Security Services | =3.7 | |
Mozilla Network Security Services | =3.7.1 | |
Mozilla Network Security Services | =3.7.2 | |
Mozilla Network Security Services | =3.7.3 | |
Mozilla Network Security Services | =3.7.5 | |
Mozilla Network Security Services | =3.7.7 | |
Mozilla Network Security Services | =3.8 | |
Mozilla Network Security Services | =3.9 | |
Mozilla Network Security Services | =3.11.2 | |
Mozilla Network Security Services | =3.11.3 | |
Mozilla Network Security Services | =3.11.4 | |
Mozilla Network Security Services | =3.11.5 | |
Mozilla Network Security Services | =3.12 | |
Mozilla Network Security Services | =3.12.1 | |
Mozilla Network Security Services | =3.12.2 | |
Mozilla Network Security Services | =3.12.3 | |
Mozilla Network Security Services | =3.12.3.1 | |
Mozilla Network Security Services | =3.12.3.2 | |
Mozilla Network Security Services | =3.12.4 | |
Mozilla Network Security Services | =3.12.5 | |
Mozilla Network Security Services | =3.12.6 | |
Mozilla Network Security Services | =3.12.7 | |
Mozilla Network Security Services | =3.12.8 | |
Mozilla Network Security Services | =3.12.9 | |
Mozilla Network Security Services | =3.12.10 | |
Mozilla Network Security Services | =3.12.11 | |
Mozilla Network Security Services | =3.14 | |
Mozilla Network Security Services | =3.14.1 | |
Mozilla Network Security Services | =3.14.2 | |
Mozilla Network Security Services | =3.14.3 | |
Mozilla Network Security Services | =3.14.4 | |
Mozilla Network Security Services | =3.14.5 | |
Mozilla Network Security Services | =3.15 | |
Mozilla Network Security Services | =3.15.1 | |
Mozilla Network Security Services | =3.15.2 | |
redhat/nss | <3.15.4 | 3.15.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.