First published: Mon Jul 06 2020(Updated: )
USN-4417-1 fixed a vulnerability in NSS. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. Original advisory details: Cesar Pereida, Billy Bob Brumley, Yuval Yarom, and Nicola Tuveri discovered that NSS incorrectly handled RSA key generation. A local attacker could possibly use this issue to perform a timing attack and recover RSA keys.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libnss3 | <2:3.28.4-0ubuntu0.14.04.5+esm6 | 2:3.28.4-0ubuntu0.14.04.5+esm6 |
=14.04 | ||
All of | ||
ubuntu/libnss3 | <2:3.28.4-0ubuntu0.12.04.9 | 2:3.28.4-0ubuntu0.12.04.9 |
=12.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-4417-2 is not mentioned in the information provided.
USN-4417-2 affects Ubuntu 12.04 and Ubuntu 14.04 by providing a corresponding update for the NSS vulnerability.
The remedy for the NSS vulnerability in Ubuntu 12.04 is to install the libnss3 package version 2:3.28.4-0ubuntu0.12.04.9 or newer.
The remedy for the NSS vulnerability in Ubuntu 14.04 is to install the libnss3 package version 2:3.28.4-0ubuntu0.14.04.5+esm6 or newer.
You can find more information about USN-4417-2 on the Ubuntu Security Notices website.