Advisories ยป MGASA-2014-0391

Updated nss packages fix CVE-2014-1568

Publication date: 26 Sep 2014
Modification date: 26 Sep 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-1568

Description

Updated nss packages fix security vulnerability:

Antoine Delignat-Lavaud, security researcher at Inria Paris in team Prosecco,
reported an issue in Network Security Services (NSS) libraries affecting all
versions. He discovered that NSS is vulnerable to a variant of a signature
forgery attack previously published by Daniel Bleichenbacher. This is due to
lenient parsing of ASN.1 values involved in a signature and could lead to the
forging of RSA certificates (CVE-2014-1568).
                

References

SRPMS

4/core

3/core