Ubuntu Security Notice USN-3372-1

Discussion in 'News Aggregator' started by Packet Storm, 1 Aug 2017.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 3372-1 - It was discovered that NSS incorrectly handled certain empty SSLv2 messages. A remote attacker could possibly use this issue to cause NSS to crash, resulting in a denial of service. Karthik Bhargavan and Gaetan Leurent discovered that the DES and Triple DES ciphers were vulnerable to birthday attacks. A remote attacker could possibly use this flaw to obtain clear text data from long encrypted sessions. This update causes NSS to limit use of the same symmetric key. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...