Oval Definition:oval:com.redhat.rhsa:def:20131779
Revision Date:2013-12-03Version:637
Title:RHSA-2013:1779: mod_nss security update (Moderate)
Description:The mod_nss module provides strong cryptography for the Apache HTTP Server via the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, using the Network Security Services (NSS) security library.

  • A flaw was found in the way mod_nss handled the NSSVerifyClient setting for the per-directory context. When configured to not require a client certificate for the initial connection and only require it for a specific directory, mod_nss failed to enforce this requirement and allowed a client to access the directory when no valid client certificate was provided. (CVE-2013-4566)

    Red Hat would like to thank Albert Smith of OUSD(AT&L) for reporting this issue.

    All mod_nss users should upgrade to this updated package, which contains a backported patch to correct this issue. The httpd service must be restarted for this update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2013-4566
    CVE-2013-4566
    RHSA-2013:1779
    RHSA-2013:1779-00
    RHSA-2013:1779-02
    Platform(s):Red Hat Enterprise Linux 5
    Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND mod_nss is earlier than 0:1.0.8-8.el5_10
  • AND mod_nss is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND mod_nss is earlier than 0:1.0.8-19.el6_5
  • AND mod_nss is signed with Red Hat redhatrelease2 key
  • BACK