| From: |
| Meltem Parmaksız <meltem@pardus.org.tr> |
| To: |
| pardus-security@pardus.org.tr |
| Subject: |
| [Pardus-security] [PLSA 2011-61] Mozilla: Fraudulent SSL
Certificates |
| Date: |
| Wed, 30 Mar 2011 09:49:57 +0300 |
| Message-ID: |
| <201103300949.58055.meltem@pardus.org.tr> |
| Archive-link: |
| Article, Thread
|
------------------------------------------------------------------------
Pardus Linux Security Advisory 2011-61 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2011-03-30
Severity: 4
Type: Remote
------------------------------------------------------------------------
Summary
=======
It was discovered that several invalid HTTPS certificates were issued
and revoked. An attacker could use these to perform a man-in-the-middle
attack.
Description
===========
MFSA 2011-11: Update to HTTPS certificate blacklist
Several invalid HTTPS certificates were placed on the certificate
blacklist to prevent their misuse.
Affected packages:
Pardus 2009:
firefox, all before 3.6.15-136-39
xulrunner, all before 1.9.2.15-40-35
Resolution
==========
There are update(s) for firefox, xulrunner. You can update them via
Package Manager or with a single command from console:
pisi up firefox xulrunner
References
==========
* http://blog.mozilla.com/security/2011/03/22/firefox-block...
certificates/
* http://www.mozilla.org/security/announce/2011/mfsa2011-11...
------------------------------------------------------------------------
_______________________________________________
Pardus-Security mailing list
Pardus-Security@pardus.org.tr
http://liste.pardus.org.tr/mailman/listinfo/pardus-security
(
Log in to post comments)