Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 22 NSS Update: Critical Fix for Logjam Vulnerability

fedora
Calendar Grey June 2, 2015
Dist Fedora Esm H88
The latest release of NSS version 3.19.1 tackles the logjam vulnerability. This crucial update enhances the TLS protocol and modifies aspects of the SSL 3 protocol.
Security fix for CVE-2015-4000 Update to the upstream NSS 3.19.1 release, which includes a fix for the recently published logjam attack

Summary

Network Security Services (NSS) is a set of libraries designed to

support cross-platform development of security-enabled client and

server applications. Applications built with NSS can support SSL v2

and v3, TLS, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME, X.509

v3 certificates, and other security standards.

Update Information:

Security fix for CVE-2015-4000

Update to the upstream NSS 3.19.1 release, which includes a fix for the recently published logjam attack.

The previous 3.19 release made several notable changes related to the TLS protocol, one of them was to disable the SSL 3 protocol by default.

For the full list of changes in the 3.19 and 3.19.1 releases, please refer to the upstream release notes documents:



Change Log

* Thu May 28 2015 Kai Engert - 3.19.1-1.0 - Update to NSS 3.19.1 * Tue May 19 2015 Kai Engert - 3.19.0-1.0 - Update to NSS 3.19

References


[ 1 ] Bug #1223211 - CVE-2015-4000 LOGJAM: TLS connections which support export grade DHE key-exchange are vulnerable to MITM attacks https://bugzilla.redhat.com/show_bug.cgi?id=1223211

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update nss' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: nss
Product: Fedora 22
Version: 3.19.1
Release: 1.0.fc22
Summary: Network Security Services

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here