USN-6727-1
Dashboard / Vulnerabilities / USN-6727-1
USN-6727-1
Summary: nss vulnerabilities
Details: It was discovered that NSS incorrectly handled padding when checking PKCS#1 certificates. A remote attacker could possibly use this issue to perform Bleichenbacher-like attacks and recover private data. This issue only affected Ubuntu 20.04 LTS. (CVE-2023-4421) It was discovered that NSS had a timing side-channel when performing RSA decryption. A remote attacker could possibly use this issue to recover private data. (CVE-2023-5388) It was discovered that NSS had a timing side-channel when using certain NIST curves. A remote attacker could possibly use this issue to recover private data. (CVE-2023-6135) The NSS package contained outdated CA certificates. This update refreshes the NSS package to version 3.98 which includes the latest CA certificate bundle and other security improvements.
References: https://ubuntu.com/security/notices/USN-6727-1, https://ubuntu.com/security/CVE-2023-4421, https://ubuntu.com/security/CVE-2023-5388, https://ubuntu.com/security/CVE-2023-6135
Affected packages
Package
Name: nss
Purl: pkg:deb/ubuntu/nss@2:3.98-0ubuntu0.20.04.1?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
