Oval Definition:oval:com.ubuntu.trusty:def:20157575000
Revision Date:2016-01-08Version:1
Title:CVE-2015-7575 on Ubuntu 14.04 LTS (trusty) - medium.
Description:Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2015-7575
Platform(s):Ubuntu 14.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 14.04 LTS (trusty) is installed.
  • AND Package Information
  • The 'firefox' package in trusty was vulnerable but has been fixed (note: '43.0.4+build3-0ubuntu0.14.04.1').
  • OR The 'gnutls26' package in trusty was vulnerable but has been fixed (note: '2.12.23-12ubuntu2.4').
  • OR The 'gnutls28' package in trusty is affected and needs fixing.
  • OR The 'nss' package in trusty was vulnerable but has been fixed (note: '2:3.19.2.1-0ubuntu0.14.04.2').
  • OR The 'openjdk-6' package in trusty was vulnerable but has been fixed (note: '6b38-1.13.10-0ubuntu0.14.04.1').
  • OR The 'openjdk-7' package in trusty was vulnerable but has been fixed (note: '7u95-2.6.4-0ubuntu0.14.04.1').
  • OR NOT While related to the CVE in some way, the 'openssl' package in trusty is not affected (note: '1.0.1f-1ubuntu2.16').
  • OR NOT While related to the CVE in some way, the 'openssl098' package in trusty is not affected.
  • OR The 'polarssl' package in trusty is affected and needs fixing.
  • OR The 'thunderbird' package in trusty was vulnerable but has been fixed (note: '1:38.6.0+build1-0ubuntu0.14.04.1').
  • BACK