Updated nss packages fix security vulnerability
Publication date: 21 Jan 2014Modification date: 21 Jan 2014
Type: security
Affected Mageia releases : 3
CVE: CVE-2013-1740
Description
Updated nss packages fix security vulnerability: The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is enabled, allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary X.509 certificate during certain handshake traffic (CVE-2013-1740).
References
SRPMS
3/core
- nss-3.15.4-1.mga3