Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 442
Alerts This Week
Warning Icon 1 442

Ubuntu 13.10: USN-2030-1 Moderate: NSS Denial Of Service Risks

ubuntu
Calendar Grey November 18, 2013
Scroller Ubuntu
Numerous vulnerabilities in NSS addressed in various Ubuntu versions; incorporates support for TLS v1.3.
Several security issues were fixed in NSS.

Summary

Several security issues were fixed in NSS.

Software Description:

- nss: Network Security Service library

Details:

Multiple security issues were discovered in NSS. If a user were tricked

into connecting to a malicious server, an attacker could possibly exploit

these to cause a denial of service via application crash, potentially

execute arbitrary code, or lead to information disclosure.

This update also adds TLS v1.2 support to Ubuntu 10.04 LTS, Ubuntu 12.04

LTS, Ubuntu 12.10, and Ubuntu 13.04.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  libnss3                         2:3.15.3-0ubuntu0.13.10.1

Ubuntu 13.04:
  libnss3                         2:3.15.3-0ubuntu0.13.04.1

Ubuntu 12.10:
  libnss3                         3.15.3-0ubuntu0.12.10.1

Ubuntu 12.04 LTS:
  libnss3                         3.15.3-0ubuntu0.12.04.1

Ubuntu 10.04 LTS:
  libnss3-1d                      3.15.3-0ubuntu0.10.04.1

This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use NSS, such as Evolution and Chromium, to make all the necessary
changes.

References

https://ubuntu.com/security/notices/USN-2030-1

CVE-2013-1739, CVE-2013-1741, CVE-2013-5605, CVE-2013-5606

November 18, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.