Oval Definition:oval:org.mitre.oval:def:27025
Revision Date:2014-12-01Version:4
Title:SUSE-SU-2014:1220-1 -- Security update for mozilla-nss
Description:Mozilla NSS was updated to version 3.16.5 to fix a RSA certificate forgeryissue.MFSA 2014-73 / CVE-2014-1568: Antoine Delignat-Lavaud, security researcherat Inria Paris in team Prosecco, reported an issue in Network SecurityServices (NSS) libraries affecting all versions. He discovered that NSS isvulnerable to a variant of a signature forgery attack previously publishedby Daniel Bleichenbacher. This is due to lenient parsing of ASN.1 valuesinvolved in a signature and could lead to the forging of RSA certificates.The Advanced Threat Research team at Intel Security also independentlydiscovered and reported this issue.Security Issues: * CVE-2014-1568
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2014-1568
SUSE-SU-2014:1220-1
Platform(s):SUSE Linux Enterprise Desktop 11
SUSE Linux Enterprise Server 11
Product(s):mozilla-nss
Definition Synopsis
  • Operation system section
  • SUSE Linux Enterprise Server 11.x is installed
  • OR SUSE Linux Enterprise Desktop 11.x is installed
  • AND Packages match section
  • libfreebl3 RPM is earlier than 0:3.16.5-0.7.1
  • OR libsoftokn3 RPM is earlier than 0:3.16.5-0.7.1
  • OR mozilla-nss RPM is earlier than 0:3.16.5-0.7.1
  • OR mozilla-nss-tools RPM is earlier than 0:3.16.5-0.7.1
  • OR libfreebl3-32bit RPM is earlier than 0:3.16.5-0.7.1
  • OR libsoftokn3-32bit RPM is earlier than 0:3.16.5-0.7.1
  • OR mozilla-nss-32bit RPM is earlier than 0:3.16.5-0.7.1
  • BACK