MGASA-2019-0038 - Updated nss packages fix security vulnerability

Publication date: 15 Jan 2019
URL: https://advisories.mageia.org/MGASA-2019-0038.html
Type: security
Affected Mageia releases: 6
CVE: CVE-2018-0495

Keegan Ryan discovered that NSS incorrectly handled ECDSA key generation.
A local attacker could possibly use this issue to perform a cache-timing
attack and recover private ECDSA keys (CVE-2018-0495).

References:
- https://bugs.mageia.org/show_bug.cgi?id=24179
- https://ubuntu.com/security/notices/USN-3850-1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0495

SRPMS:
- 6/core/nss-3.36.6-1.1.mga6

Mageia 2019-0038: nss security update

Keegan Ryan discovered that NSS incorrectly handled ECDSA key generation

Summary

Keegan Ryan discovered that NSS incorrectly handled ECDSA key generation. A local attacker could possibly use this issue to perform a cache-timing attack and recover private ECDSA keys (CVE-2018-0495).

References

- https://bugs.mageia.org/show_bug.cgi?id=24179

- https://ubuntu.com/security/notices/USN-3850-1

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0495

Resolution

MGASA-2019-0038 - Updated nss packages fix security vulnerability

SRPMS

- 6/core/nss-3.36.6-1.1.mga6

Severity
Publication date: 15 Jan 2019
URL: https://advisories.mageia.org/MGASA-2019-0038.html
Type: security
CVE: CVE-2018-0495

Related News