Oval Definition:oval:org.mitre.oval:def:28139
Revision Date:2015-01-26Version:10
Title:RHSA-2014:1948 -- nss, nss-util, and nss-softokn security, bug fix, and enhancement update (Important)
Description:Network Security Services (NSS) is a set of libraries designed to supportthe cross-platform development of security-enabled client and serverapplications. Netscape Portable Runtime (NSPR) provides platformindependence for non-GUI operating system facilities.This update adds support for the TLS Fallback Signaling Cipher Suite Value(TLS_FALLBACK_SCSV), which can be used to prevent protocol downgradeattacks against applications which re-connect using a lower SSL/TLSprotocol version when the initial connection indicating the highestsupported protocol version fails.This can prevent a forceful downgrade of the communication to SSL 3.0.The SSL 3.0 protocol was found to be vulnerable to the padding oracleattack when using block cipher suites in cipher block chaining (CBC) mode.This issue is identified as CVE-2014-3566, and also known under the aliasPOODLE. This SSL 3.0 protocol flaw will not be addressed in a futureupdate; it is recommended that users configure their applications torequire at least TLS protocol version 1.0 for secure communication.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2014:1948-CentOS 5
CESA-2014:1948-CentOS 6
CESA-2014:1948-CentOS 7
RHSA-2014:1948
Platform(s):CentOS Linux 5
CentOS Linux 6
CentOS Linux 7
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Product(s):nss
Definition Synopsis
  • Red Hat Enterprise Linux 5 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 5
  • AND nss-debuginfo is earlier than 0:3.16.2.3-1.el5_11
  • Red Hat Enterprise Linux 5 and CentOS Linux 5 release section
  • Operation system section
  • The operating system installed on the system is Red Hat Enterprise Linux 5
  • OR The operating system installed on the system is CentOS Linux 5.x
  • AND Packages match section
  • nss-devel is earlier than 0:3.16.2.3-1.el5_11
  • OR nss-pkcs11-devel is earlier than 0:3.16.2.3-1.el5_11
  • OR nss is earlier than 0:3.16.2.3-1.el5_11
  • OR nss-tools is earlier than 0:3.16.2.3-1.el5_11
  • Red Hat Enterprise Linux 6 and CentOS Linux 6 release section
  • Operation system section
  • The operating system installed on the system is Red Hat Enterprise Linux 6
  • OR The operating system installed on the system is CentOS Linux 6.x
  • AND Packages match section
  • nss is earlier than 0:3.16.2.3-3.el6_6
  • OR nss-devel is earlier than 0:3.16.2.3-3.el6_6
  • OR nss-pkcs11-devel is earlier than 0:3.16.2.3-3.el6_6
  • OR nss-sysinit is earlier than 0:3.16.2.3-3.el6_6
  • OR nss-tools is earlier than 0:3.16.2.3-3.el6_6
  • OR nss-util is earlier than 0:3.16.2.3-2.el6_6
  • OR nss-util-devel is earlier than 0:3.16.2.3-2.el6_6
  • Red Hat Enterprise Linux 6 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 6
  • AND Packages match section
  • nss-debuginfo is earlier than 0:3.16.2.3-3.el6_6
  • OR nss-util-debuginfo is earlier than 0:3.16.2.3-2.el6_6
  • Red Hat Enterprise Linux 7 and CentOS Linux 7 release section
  • Operation system section
  • The operating system installed on the system is Red Hat Enterprise Linux 7
  • OR The operating system installed on the system is CentOS Linux 7.x
  • AND Packages match section
  • nss is earlier than 0:3.16.2.3-2.el7_0
  • OR nss-devel is earlier than 0:3.16.2.3-2.el7_0
  • OR nss-pkcs11-devel is earlier than 0:3.16.2.3-2.el7_0
  • OR nss-softokn is earlier than 0:3.16.2.3-1.el7_0
  • OR nss-softokn-devel is earlier than 0:3.16.2.3-1.el7_0
  • OR nss-softokn-freebl is earlier than 0:3.16.2.3-1.el7_0
  • OR nss-softokn-freebl-devel is earlier than 0:3.16.2.3-1.el7_0
  • OR nss-sysinit is earlier than 0:3.16.2.3-2.el7_0
  • OR nss-tools is earlier than 0:3.16.2.3-2.el7_0
  • OR nss-util is earlier than 0:3.16.2.3-1.el7_0
  • OR nss-util-devel is earlier than 0:3.16.2.3-1.el7_0
  • Red Hat Enterprise Linux 7 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 7
  • AND Packages match section
  • nss-debuginfo is earlier than 0:3.16.2.3-2.el7_0
  • OR nss-softokn-debuginfo is earlier than 0:3.16.2.3-1.el7_0
  • OR nss-util-debuginfo is earlier than 0:3.16.2.3-1.el7_0
  • BACK