Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian DSA-3033-1 Critical: NSS ASN.1 Signature Forgery Attack

debian
Calendar Grey September 25, 2014
Debian Logo
Ubuntu security patch for openssl resolves ASN.1 decoding vulnerability resulting in cryptographic signature forgery. Urgent update advised.
Antoine Delignat-Lavaud from Inria discovered an issue in the way NSS (the Mozilla Network Security Service library) was parsing ASN.1 data used in signatures, making it vulnerable...

Summary

Antoine Delignat-Lavaud from Inria discovered an issue in the way NSS
(the Mozilla Network Security Service library) was parsing ASN.1 data
used in signatures, making it vulnerable to a signature forgery attack.

An attacker could craft ASN.1 data to forge RSA certificates with a
valid certification chain to a trusted CA.

For the stable distribution (wheezy), this problem has been fixed in
version 2:3.14.5-1+deb7u2.

For the testing distribution (jessie), this problem has been fixed in
version 2:3.17.1.

For the unstable distribution (sid), this problem has been fixed in
version 2:3.17.1.

We recommend that you upgrade your nss packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: nss
CVE ID: CVE-2014-1568

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here