Oval Definition:oval:com.redhat.rhsa:def:20191951
Revision Date:2019-07-30Version:638
Title:RHSA-2019:1951: nss and nspr security, bug fix, and enhancement update (Moderate)
Description:Network Security Services (NSS) is a set of libraries designed to support the cross-platform development of security-enabled client and server applications.

Netscape Portable Runtime (NSPR) provides platform independence for non-GUI operating system facilities.

  • The following packages have been upgraded to a later upstream version: nss (3.44.0), nspr (4.21.0). (BZ#1713187, BZ#1713188)

    Security Fix(es):

  • nss: NULL pointer dereference in several CMS functions resulting in a denial of service (CVE-2018-18508)

  • nss: Out-of-bounds read when importing curve25519 private key (CVE-2019-11719)

  • nss: Empty or malformed p256-ECDH public keys may trigger a segmentation fault (CVE-2019-11729)

  • nss: PKCS#1 v1.5 signatures can be used for TLS 1.3 (CVE-2019-11727)

    For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

    Bug Fix(es):

  • PQG verify fails when create DSA PQG parameters because the counts aren't returned correctly. (BZ#1685325)

  • zeroization of AES context missing (BZ#1719629)

  • RSA Pairwise consistency test (BZ#1719630)

  • FIPS updated for nss-softoken POST (BZ#1722373)

  • DH/ECDH key tests missing for the PG parameters (BZ#1722374)

  • NSS should implement continuous random test on it's seed data or use the kernel AF_ALG interface for random (BZ#1725059)

  • support setting supported signature algorithms in strsclnt utility (BZ#1725110)

  • certutil -F with no parameters is killed with segmentation fault message (BZ#1725115)

  • NSS: Support for IKE/IPsec typical PKIX usage so libreswan can use nss without rejecting certs based on EKU (BZ#1725116)

  • NSS should use getentropy() for seeding its RNG, not /dev/urandom. Needs update to NSS 3.37 (BZ#1725117)

  • Disable TLS 1.3 in FIPS mode (BZ#1725773)

  • Wrong alert sent when client uses PKCS#1 signatures in TLS 1.3 (BZ#1728259)

  • x25519 allowed in FIPS mode (BZ#1728260)

  • post handshake authentication with selfserv does not work if SSL_ENABLE_SESSION_TICKETS is set (BZ#1728261)

    Enhancement(s):

  • Move IKEv1 and IKEv2 KDF's from libreswan to nss-softkn (BZ#1719628)
  • Family:unixClass:patch
    Status:Reference(s):CVE-2018-18508
    CVE-2019-11719
    CVE-2019-11727
    CVE-2019-11729
    CVE-2019-17007
    RHSA-2019:1951
    Platform(s):Red Hat Enterprise Linux 8
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 8 is installed
  • OR Red Hat CoreOS 4 is installed
  • AND
  • nspr is earlier than 0:4.21.0-2.el8_0
  • AND nspr is signed with Red Hat redhatrelease2 key
  • nspr-devel is earlier than 0:4.21.0-2.el8_0
  • AND nspr-devel is signed with Red Hat redhatrelease2 key
  • nss is earlier than 0:3.44.0-7.el8_0
  • AND nss is signed with Red Hat redhatrelease2 key
  • nss-devel is earlier than 0:3.44.0-7.el8_0
  • AND nss-devel is signed with Red Hat redhatrelease2 key
  • nss-softokn is earlier than 0:3.44.0-7.el8_0
  • AND nss-softokn is signed with Red Hat redhatrelease2 key
  • nss-softokn-devel is earlier than 0:3.44.0-7.el8_0
  • AND nss-softokn-devel is signed with Red Hat redhatrelease2 key
  • nss-softokn-freebl is earlier than 0:3.44.0-7.el8_0
  • AND nss-softokn-freebl is signed with Red Hat redhatrelease2 key
  • nss-softokn-freebl-devel is earlier than 0:3.44.0-7.el8_0
  • AND nss-softokn-freebl-devel is signed with Red Hat redhatrelease2 key
  • nss-sysinit is earlier than 0:3.44.0-7.el8_0
  • AND nss-sysinit is signed with Red Hat redhatrelease2 key
  • nss-tools is earlier than 0:3.44.0-7.el8_0
  • AND nss-tools is signed with Red Hat redhatrelease2 key
  • nss-util is earlier than 0:3.44.0-7.el8_0
  • AND nss-util is signed with Red Hat redhatrelease2 key
  • nss-util-devel is earlier than 0:3.44.0-7.el8_0
  • AND nss-util-devel is signed with Red Hat redhatrelease2 key
  • BACK