Ubuntu Security Notice USN-3850-1

Discussion in 'News Aggregator' started by Packet Storm, 10 Jan 2019.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 3850-1 - Keegan Ryan discovered that NSS incorrectly handled ECDSA key generation. A local attacker could possibly use this issue to perform a cache-timing attack and recover private ECDSA keys. It was discovered that NSS incorrectly handled certain v2-compatible ClientHello messages. A remote attacker could possibly use this issue to perform a replay attack. It was discovered that NSS incorrectly handled certain padding oracles. A remote attacker could possibly use this issue to perform a variant of the Bleichenbacher attack. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...