Red Hat Security Advisory 2015-1664-01

Discussion in 'News Aggregator' started by Packet Storm, 25 Aug 2015.

  1. Packet Storm

    Packet Storm Guest

    Red Hat Security Advisory 2015-1664-01 - Network Security Services is a set of libraries designed to support cross-platform development of security-enabled client and server applications. It was found that NSS permitted skipping of the ServerKeyExchange packet during a handshake involving ECDHE. A remote attacker could use this flaw to bypass the forward-secrecy of a TLS/SSL connection. A flaw was found in the way NSS verified certain ECDSA signatures. Under certain conditions, an attacker could use this flaw to conduct signature forgery attacks.

    Continue reading...
     

Share This Page

Loading...