Oval Definition:oval:com.redhat.rhsa:def:20100862
Revision Date:2010-11-10Version:639
Title:RHSA-2010:0862: nss security update (Low)
Description:Network Security Services (NSS) is a set of libraries designed to support the development of security-enabled client and server applications.

  • A flaw was found in the way NSS matched SSL certificates when the certificates had a Common Name containing a wildcard and a partial IP address. NSS incorrectly accepted connections to IP addresses that fell within the SSL certificate's wildcard range as valid SSL connections, possibly allowing an attacker to conduct a man-in-the-middle attack. (CVE-2010-3170)

    All NSS users should upgrade to these updated packages, which provide NSS version 3.12.8 to resolve this issue. After installing the update, applications using NSS must be restarted for the changes to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2010-3170
    CVE-2010-3170
    RHSA-2010:0862
    RHSA-2010:0862-02
    RHSA-2010:0862-02
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • nss is earlier than 0:3.12.8-1.el6_0
  • AND nss is signed with Red Hat redhatrelease2 key
  • nss-devel is earlier than 0:3.12.8-1.el6_0
  • AND nss-devel is signed with Red Hat redhatrelease2 key
  • nss-pkcs11-devel is earlier than 0:3.12.8-1.el6_0
  • AND nss-pkcs11-devel is signed with Red Hat redhatrelease2 key
  • nss-sysinit is earlier than 0:3.12.8-1.el6_0
  • AND nss-sysinit is signed with Red Hat redhatrelease2 key
  • nss-tools is earlier than 0:3.12.8-1.el6_0
  • AND nss-tools is signed with Red Hat redhatrelease2 key
  • nss-util is earlier than 0:3.12.8-1.el6_0
  • AND nss-util is signed with Red Hat redhatrelease2 key
  • nss-util-devel is earlier than 0:3.12.8-1.el6_0
  • AND nss-util-devel is signed with Red Hat redhatrelease2 key
  • nss-softokn is earlier than 0:3.12.8-1.el6_0
  • AND nss-softokn is signed with Red Hat redhatrelease2 key
  • nss-softokn-devel is earlier than 0:3.12.8-1.el6_0
  • AND nss-softokn-devel is signed with Red Hat redhatrelease2 key
  • nss-softokn-freebl is earlier than 0:3.12.8-1.el6_0
  • AND nss-softokn-freebl is signed with Red Hat redhatrelease2 key
  • BACK