USN-3270-1: NSS vulnerabilities
Karthik Bhargavan and Gaetan Leurent discovered that the DES and Triple DES ciphers were vulnerable to birthday attacks. A remote attacker could possibly use this flaw to obtain clear text data from long encrypted sessions. This update causes NSS to limit use of the same symmetric key. (CVE-2016-2183) It was discovered that NSS incorrectly handled Base64 decoding. A remote attacker could use this flaw to cause NSS to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2017-5461) This update refreshes the NSS package to version 3.28.4 which includes the latest CA certificate bundle.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-3270-1?
The severity of USN-3270-1 is considered high due to the potential for remote attackers to exploit the vulnerability and obtain clear text data.
How do I fix USN-3270-1?
To fix USN-3270-1, update the libnss3 package to the latest version provided in the security bulletin for your Ubuntu version.
Which Ubuntu versions are affected by USN-3270-1?
USN-3270-1 affects Ubuntu 14.04, 16.04, 16.10, and 17.04 due to vulnerabilities in the DES and Triple DES ciphers.
What types of attacks are possible due to USN-3270-1?
USN-3270-1 allows for birthday attacks which could result in the decryption of long encrypted sessions.
Who discovered the vulnerability in USN-3270-1?
The vulnerabilities addressed in USN-3270-1 were discovered by Karthik Bhargavan and Gaetan Leurent.