Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian: DSA-2141-2 Critical Update: NSS SSL/TLS Protocol Flaw

debian
Calendar Grey January 5, 2011
Debian Logo
Patch for nss addresses SSL/TLS insecure renegotiation vulnerability within Debian environments. Users are advised to upgrade to shield against potential remote exploits.
CVE-2009-3555: Marsh Ray, Steve Dispensa, and Martin Rex discovered a flaw in the TLS and SSLv3 protocols

Summary

Marsh Ray, Steve Dispensa, and Martin Rex discovered a flaw in the TLS
and SSLv3 protocols. If an attacker could perform a man in the middle
attack at the start of a TLS connection, the attacker could inject
arbitrary content at the beginning of the user's session. This update
adds backported support for the new RFC5746 renegotiation extension
which fixes this issue.

The updated libraries allow to use shell environment variables to
configure if insecure renegotiation is still allowed. The syntax of
these environment variables is described in the release notes to
version 3.12.6 of nss:


However, the default behaviour for nss in Debian 5.0 (Lenny) is
NSS_SSL_ENABLE_RENEGOTIATION=3, which allows clients to continue to
renegotiate with vulnerable servers.

For the stable distribution (lenny), this problem has been fixed
in version 3.12.3.1-0lenny3.

For the unstable distribution (sid), and the testing distribution
(squeeze), this problem has been fixed in version 3.12.6-1.

We recommend that you upgrade y...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: nss
CVE ID: CVE-2009-3555

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here