UbuntuUpdates.org

Bugs fixes in "nss"

Origin Bug number Title Date fixed
CVE CVE-2018-12404 Cache side-channel variant of the Bleichenbacher attack 2019-01-09
CVE CVE-2018-12384 ServerHello.random is all zero when handling a v2-compatible ClientHello 2019-01-09
CVE CVE-2018-0495 Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of 2019-01-09
CVE CVE-2018-12404 Cache side-channel variant of the Bleichenbacher attack 2019-01-09
CVE CVE-2018-12384 ServerHello.random is all zero when handling a v2-compatible ClientHello 2019-01-09
CVE CVE-2018-0495 Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of 2019-01-09
CVE CVE-2018-12404 Cache side-channel variant of the Bleichenbacher attack 2019-01-09
CVE CVE-2018-12384 ServerHello.random is all zero when handling a v2-compatible ClientHello 2019-01-09
CVE CVE-2018-0495 Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of 2019-01-09
CVE CVE-2018-12404 Cache side-channel variant of the Bleichenbacher attack 2019-01-09
CVE CVE-2018-12384 ServerHello.random is all zero when handling a v2-compatible ClientHello 2019-01-09
CVE CVE-2018-0495 Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of 2019-01-09
CVE CVE-2017-7502 Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by re 2017-06-21
CVE CVE-2017-7502 Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by re 2017-06-21
CVE CVE-2017-7502 Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by re 2017-06-21
CVE CVE-2017-7502 Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by re 2017-06-21
CVE CVE-2017-7502 Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by re 2017-06-21
CVE CVE-2017-7502 Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by re 2017-06-21
CVE CVE-2016-2183 The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately 2017-04-27
CVE CVE-2016-2183 The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately 2017-04-27



About   -   Send Feedback to @ubuntu_updates