Oval Definition:oval:org.mitre.oval:def:13182
Revision Date:2014-06-30Version:20
Title:USN-927-2 -- nss regression
Description:USN-927-1 fixed vulnerabilities in NSS. Upstream NSS 3.12.6 added an additional checksum verification on libnssdbm3.so, but the Ubuntu packaging did not create this checksum. As a result, Firefox could not initialize the security component when the NSS Internal FIPS PKCS #11 Module was enabled. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Marsh Ray and Steve Dispensa discovered a flaw in the TLS and SSLv3 protocols. If an attacker could perform a man in the middle attack at the start of a TLS connection, the attacker could inject arbitrary content at the beginning of the user�s session. This update adds support for the new new renegotiation extension and will use it when the server supports it.
Family:unixClass:patch
Status:ACCEPTEDReference(s):USN-927-2
USN-927-2
Platform(s):Ubuntu 9.10
Product(s):nss
Definition Synopsis
  • Ubuntu 9.10 is installed
  • AND Supported architectures section
  • Installed architecture is sparc
  • OR Installed architecture is i386
  • OR Installed architecture is amd64
  • OR Installed architecture is lpia
  • OR Installed architecture is powerpc
  • AND Packages section
  • libnss3-dev DPKG is earlier than 3.12.6-0ubuntu0.9.10.2
  • OR libnss3-1d-dbg DPKG is earlier than 3.12.6-0ubuntu0.9.10.2
  • OR libnss3-0d DPKG is earlier than 3.12.6-0ubuntu0.9.10.2
  • OR libnss3-1d DPKG is earlier than 3.12.6-0ubuntu0.9.10.2
  • OR libnss3-tools DPKG is earlier than 3.12.6-0ubuntu0.9.10.2
  • BACK