Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 2019-0038 Moderate: NSS ECDSA Key Recovery Vulnerability

mageia
Calendar Grey January 15, 2019
Dist Mageia Esm H88
MGASA-2019-0038 - Updated nss packages fix security vulnerability Publication date: 15 Jan 2019 URL:
Keegan Ryan discovered that NSS incorrectly handled ECDSA key generation

Summary

Keegan Ryan discovered that NSS incorrectly handled ECDSA key generation. A local attacker could possibly use this issue to perform a cache-timing attack and recover private ECDSA keys (CVE-2018-0495).

References

- https://bugs.mageia.org/show_bug.cgi?id=24179

- https://ubuntu.com/security/notices/USN-3850-1

- https://www.cve.org/CVERecord?id=CVE-2018-0495

Resolution

SRPMS

- 6/core/nss-3.36.6-1.1.mga6

Publication date: 15 Jan 2019
URL: https://advisories.mageia.org/MGASA-2019-0038.html
Type: security
CVE: CVE-2018-0495

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here