Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 10 DLA-3634-1 Critical: NSS Denial Of Service And Timing Attack

debian lts
Calendar Grey October 28, 2023
Dist Debian Esm H88
Important alert regarding Debian LTS DLA-3634-2, which resolves a series of vulnerabilities found in the nss packages. Users are advised to perform an upgrade as soon as possible.
Multiple vulnerabilities were found in nss, a set of libraries designed to support cross-platform development of security-enabled client and server applications

Summary

CVE-2020-25648

A flaw was discovered in how NSS handles CipherChangeSpec messages
in TLS 1.3. It could allow an attacker to send multiple CCS
messages to servers compiled against NSS, causing denial-of-service.

CVE-2023-4421

A fuzzing project discovered vulnerabilities to Bleichenbacher
timing attacks in NSS's facilities for RSA cryptography.

For Debian 10 buster, these problems have been fixed in version
2:3.42.1-1+deb10u7.

We recommend that you upgrade your nss packages.

For the detailed security status of nss please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/nss

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: nss
Version: 2:3.42.1-1+deb10u7
CVE ID: CVE-2020-25648 CVE-2023-4421

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here