Updated nss packages fix security vulnerability
Publication date: 21 Jan 2014Modification date: 21 Jan 2014
Type: security
Affected Mageia releases : 3
CVE: CVE-2013-1740
Description
Updated nss packages fix security vulnerability:
The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla
Network Security Services (NSS) before 3.15.4, when the TLS False
Start feature is enabled, allows man-in-the-middle attackers to spoof
SSL servers by using an arbitrary X.509 certificate during certain
handshake traffic (CVE-2013-1740).
References
SRPMS
3/core
- nss-3.15.4-1.mga3