Oval Definition:oval:com.ubuntu.disco:def:2019170230000000
Revision Date:2020-01-08Version:1
Title:CVE-2019-17023 on Ubuntu 19.04 (disco) - low.
Description:After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects Firefox < 72.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2019-17023
Platform(s):Ubuntu 19.04
Product(s):
Definition Synopsis
  • Ubuntu 19.04 (disco) is installed.
  • AND Package Information
  • firefox package in disco was vulnerable but has been fixed (note: '72.0.1+build1-0ubuntu0.19.04.1').
  • OR mozjs52 package in disco is affected and may need fixing.
  • OR mozjs60 package in disco is affected and may need fixing.
  • OR nss package in disco is affected and may need fixing.
  • BACK