Site icon 지락문화예술공작단

USN-2864-1: NSS vulnerability

Ubuntu Security Notice USN-2864-1

7th January, 2016

nss vulnerability

A security issue affects these releases of Ubuntu and its
derivatives:

Summary

NSS could be made to expose sensitive information over the network.

Software description

Details

Karthikeyan Bhargavan and Gaetan Leurent discovered that NSS incorrectly
allowed MD5 to be used for TLS 1.2 connections. If a remote attacker were
able to perform a man-in-the-middle attack, this flaw could be exploited to
view sensitive information.

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 15.10:
libnss3

2:3.19.2.1-0ubuntu0.15.10.2
Ubuntu 15.04:
libnss3

2:3.19.2.1-0ubuntu0.15.04.2
Ubuntu 14.04 LTS:
libnss3

2:3.19.2.1-0ubuntu0.14.04.2
Ubuntu 12.04 LTS:
libnss3

3.19.2.1-0ubuntu0.12.04.2

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

After a standard system update you need to restart any applications that
use NSS, such as Evolution and Chromium, to make all the necessary changes.

References

CVE-2015-7575

Source: ubuntu-usn

Exit mobile version