USN-3372-1: NSS vulnerability
It was discovered that NSS incorrectly handled certain empty SSLv2 messages. A remote attacker could possibly use this issue to cause NSS to crash, resulting in a denial of service. (CVE-2017-7502) Karthik Bhargavan and Gaetan Leurent discovered that the DES and Triple DES ciphers were vulnerable to birthday attacks. A remote attacker could possibly use this flaw to obtain clear text data from long encrypted sessions. This update causes NSS to limit use of the same symmetric key. (CVE-2016-2183) It was discovered that NSS incorrectly handled Base64 decoding. A remote attacker could use this flaw to cause NSS to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2017-5461)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-3372-1?
The severity of USN-3372-1 is classified as a denial of service vulnerability that could crash the NSS library.
How do I fix USN-3372-1?
To fix USN-3372-1, upgrade the libnss3 package to version 2:3.28.4-0ubuntu0.12.04.1 or later.
What versions of Ubuntu are affected by USN-3372-1?
Ubuntu 12.04 is affected by USN-3372-1.
What causes the vulnerability in USN-3372-1?
The vulnerability in USN-3372-1 is caused by NSS incorrectly handling empty SSLv2 messages.
Can USN-3372-1 be exploited remotely?
Yes, a remote attacker could exploit USN-3372-1 to crash the NSS library, leading to denial of service.