Mandriva Linux Security Advisory MDVSA-2014:189
http://www.mandriva.com/en/
______________________________
Package : nss
Date : September 25, 2014
Affected: Business Server 1.0
______________________________
Problem Description:
A vulnerability has been discovered and corrected in Mozilla NSS:
Antoine Delignat-Lavaud, security researcher at Inria Paris in
team Prosecco, reported an issue in Network Security Services (NSS)
libraries affecting all versions. He discovered that NSS is vulnerable
to a variant of a signature forgery attack previously published
by Daniel Bleichenbacher. This is due to lenient parsing of ASN.1
values involved in a signature and could lead to the forging of RSA
certificates (CVE-2014-1568).
The updated NSPR packages have been upgraded to the latest 4.10.7
version.
The updated NSS packages have been upgraded to the latest 3.17.1
version which is not vulnerable to this issue.
Additionally the rootcerts package has also been updated to the latest
version as of 2014-08-05.
______________________________
References:
http://cve.mitre.org/cgi-bin/
https://www.mozilla.org/
______________________________
Updated Packages:
Mandriva Business Server 1/X86_64:
d532128922a8701f24f1d1a22b8e54
86c469bff7f47669ecfbe711fced77
a5384df3378e1d282d24520fe92348
63722882484c4e4a4b438ddb33911f
5a9c51abf5c3650926e4cdb8997ec2
8b639de0098277bc211ed8b9f83c95
edd4b951a0f68c4264137489f0dada
32f6ffafd4984d00b01b43e9b38fe3
fa908930395265a0dbad1029252679
fb338172cf421a95728ec28412d2fe
3c721493672c05aa7960aca11e3b15
8b79fa2baeaac0b531d7cb01c5a419
______________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/en/
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
Komentarų nėra:
Rašyti komentarą