USN-4060-1
Dashboard / Vulnerabilities / USN-4060-1
USN-4060-1
Summary: nss vulnerabilities
Details: Henry Corrigan-Gibbs discovered that NSS incorrectly handled importing certain curve25519 private keys. An attacker could use this issue to cause NSS to crash, resulting in a denial of service, or possibly obtain sensitive information. (CVE-2019-11719) Hubert Kario discovered that NSS incorrectly handled PKCS#1 v1.5 signatures when using TLSv1.3. An attacker could possibly use this issue to trick NSS into using PKCS#1 v1.5 signatures, contrary to expectations. This issue only applied to Ubuntu 19.04. (CVE-2019-11727) Jonas Allmann discovered that NSS incorrectly handled certain p256-ECDH public keys. An attacker could possibly use this issue to cause NSS to crash, resulting in a denial of service. (CVE-2019-11729)
References: https://ubuntu.com/security/notices/USN-4060-1, https://ubuntu.com/security/CVE-2019-11719, https://ubuntu.com/security/CVE-2019-11727, https://ubuntu.com/security/CVE-2019-11729
Affected packages
Package
Name: nss
Purl: pkg:deb/ubuntu/nss@2:3.28.4-0ubuntu0.16.04.6?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
