CVE-2015-2721: Medium severity suse linux enterprise software development kit vulnerability
Last updated 24 July 2024
Other sources
Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS state machine, which allows man-in-the-middle attackers to defeat cryptographic protection mechanisms by blocking messages, as demonstrated by removing a forward-secrecy property by blocking a ServerKeyExchange message, aka a "SMACK SKIP-TLS" issue.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-2721?
CVE-2015-2721 is a vulnerability in Mozilla Network Security Services (NSS) that allows man-in-the-middle attacks.
Which products are affected by CVE-2015-2721?
Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products are affected by CVE-2015-2721.
What is the severity of CVE-2015-2721?
The severity of CVE-2015-2721 is medium, with a severity value of 4.3.
How do I fix CVE-2015-2721 in Debian-based systems?
To fix CVE-2015-2721 in Debian-based systems, update the nss package to version 2:3.42.1-1+deb10u5, 2:3.42.1-1+deb10u6, 2:3.61-1+deb11u3, 2:3.87.1-1, or 2:3.93-1, depending on your specific release.
How do I fix CVE-2015-2721 in Ubuntu-based systems?
To fix CVE-2015-2721 in Ubuntu-based systems, update the nss package to version 2:3.19.2-0ubuntu15.04.1 (for Ubuntu 15.04), 2:3.19.1-1 (for Ubuntu 15.04), 2:3.19.2-0ubuntu0.14.04.1 (for Ubuntu 14.04), or 2:3.19.2-0ubuntu0.14.10.1 (for Ubuntu 14.10), depending on your specific release.