Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 22: FEDORA-2015-9342 Low: NSS-PKI Vulnerability Patch

fedora
Calendar Grey June 1, 2015
Dist Fedora Esm H88
Ubuntu 16.04 patch resolves poodle attack issues in libssl package with crucial enhancements to security.
Security fix for CVE-2015-4000 Update to the upstream NSS 3.19.1 release, which includes a fix for the recently published logjam attack

Summary

Utilities for Network Security Services and the Softoken module

Update Information:

Security fix for CVE-2015-4000

Update to the upstream NSS 3.19.1 release, which includes a fix for the recently published logjam attack.

The previous 3.19 release made several notable changes related to the TLS protocol, one of them was to disable the SSL 3 protocol by default.

For the full list of changes in the 3.19 and 3.19.1 releases, please refer to the upstream release notes documents:



Change Log

* Thu May 28 2015 Kai Engert - 3.19.1-1.0 - Update to NSS 3.19.1 * Tue May 19 2015 Kai Engert - 3.19.0-1.0 - Update to NSS 3.19 * Thu Mar 19 2015 Elio Maldonado - 3.18.0-1 - Update to nss-3.18.0 * Wed Jan 28 2015 Elio Maldonado - 3.17.4-1 - Update to nss-3.17.4 * Fri Dec 5 2014 Elio Maldonado - 3.17.3-1 - Update to nss-3.17.3

References


[ 1 ] Bug #1223211 - CVE-2015-4000 LOGJAM: TLS connections which support export grade DHE key-exchange are vulnerable to MITM attacks https://bugzilla.redhat.com/show_bug.cgi?id=1223211

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update nss-util' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
low
Lowest
Low
Medium
High
Critical

Name: nss-util
Product: Fedora 21
Version: 3.19.1
Release: 1.0.fc21
Summary: Network Security Services Utilities Library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here