Rapid7 Vulnerability & Exploit Database

RHSA-2014:1073: nss, nss-util, nss-softokn security, bug fix, and enhancement update

Back to Search

RHSA-2014:1073: nss, nss-util, nss-softokn security, bug fix, and enhancement update

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
03/25/2014
Created
07/25/2018
Added
09/24/2014
Modified
07/04/2017

Description

Network Security Services (NSS) is a set of libraries designed to supportthe cross-platform development of security-enabled client and serverapplications. Applications built with NSS can support SSLv3, TLS, and othersecurity standards.It was found that the implementation of Internationalizing Domain Names inApplications (IDNA) hostname matching in NSS did not follow the RFC 6125recommendations. This could lead to certain invalid certificates withinternational characters to be accepted as valid. (CVE-2014-1492)In addition, the nss, nss-util, and nss-softokn packages have been upgradedto upstream version 3.16.2, which provides a number of bug fixes andenhancements over the previous versions. (BZ#1124659)Users of NSS are advised to upgrade to these updated packages, whichcorrect these issues and add these enhancements. After installing thisupdate, applications using NSS must be restarted for this update totake effect.

Solution(s)

  • redhat-upgrade-nss
  • redhat-upgrade-nss-debuginfo
  • redhat-upgrade-nss-devel
  • redhat-upgrade-nss-pkcs11-devel
  • redhat-upgrade-nss-softokn
  • redhat-upgrade-nss-softokn-debuginfo
  • redhat-upgrade-nss-softokn-devel
  • redhat-upgrade-nss-softokn-freebl
  • redhat-upgrade-nss-softokn-freebl-devel
  • redhat-upgrade-nss-sysinit
  • redhat-upgrade-nss-tools
  • redhat-upgrade-nss-util
  • redhat-upgrade-nss-util-debuginfo
  • redhat-upgrade-nss-util-devel

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;