Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 21 FEDORA-2015-9130 Critical: NSS Logjam Fix Details

fedora
Calendar Grey June 1, 2015
Dist Fedora Esm H88
Fedora 21 advisory on the nss-softokn security patch, targeting vulnerabilities linked to the Logjam exploit, implementing crucial enhancements.
Security fix for CVE-2015-4000 Update to the upstream NSS 3.19.1 release, which includes a fix for the recently published logjam attack

Summary

Network Security Services Softoken Cryptographic Module

Update Information:

Security fix for CVE-2015-4000

Update to the upstream NSS 3.19.1 release, which includes a fix for the recently published logjam attack.

The previous 3.19 release made several notable changes related to the TLS protocol, one of them was to disable the SSL 3 protocol by default.

For the full list of changes in the 3.19 and 3.19.1 releases, please refer to the upstream release notes documents:



Change Log

* Thu May 28 2015 Kai Engert - 3.19.1-1.0 - Update to NSS 3.19.1 * Tue May 19 2015 Kai Engert - 3.19.0-1.0 - Update to NSS 3.19 * Thu Mar 19 2015 Elio Maldonado - 3.18.0-1 - Update to nss-3.18.0 * Wed Jan 28 2015 Elio Maldonado - 3.17.4-1 - Update to nss-3.17.4 - fix dependencies so nss-softokn pulls in nss-softokn-freebl of the same version and release * Fri Dec 5 2014 Elio Maldonado - 3.17.3-1 - Update to nss-3.17.3 * Sat Nov 8 2014 Elio Maldonado - 3.17.2-2 - Resolves: Bug 1155306 - Provide sym key derive mechansm as result of encryption of message

References


[ 1 ] Bug #1223211 - CVE-2015-4000 LOGJAM: TLS connections which support export grade DHE key-exchange are vulnerable to MITM attacks https://bugzilla.redhat.com/show_bug.cgi?id=1223211

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update nss-softokn' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: nss-softokn
Product: Fedora 21
Version: 3.19.1
Release: 1.0.fc21
Summary: Network Security Services Softoken Module

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here