|
|
Log in / Subscribe / Register

mozilla: two vulnerabilities

Package(s):firefox thunderbird seamonkey nss CVE #(s):CVE-2015-2721 CVE-2015-2730
Created:July 6, 2015 Updated:September 28, 2015
Description: From the Mageia advisory:

Security researcher Karthikeyan Bhargavan reported an issue in Network Security Services (NSS) where the client allows for a ECDHE_ECDSA exchange where the server does not send its ServerKeyExchange message instead of aborting the handshake. Instead, the NSS client will take the EC key from the ECDSA certificate. This violates the TLS protocol and also has some security implications for forward secrecy. In this situation, the browser thinks it is engaged in an ECDHE exchange, but has been silently downgraded to a non-forward secret mixed-ECDH exchange instead. As a result, if False Start is enabled, the browser will start sending data encrypted under these non-forward-secret connection keys (CVE-2015-2721).

Mozilla community member Watson Ladd reported that the implementation of Elliptical Curve Cryptography (ECC) multiplication for Elliptic Curve Digital Signature Algorithm (ECDSA) signature validation in Network Security Services (NSS) did not handle exceptional cases correctly. This could potentially allow for signature forgery (CVE-2015-2730).

Alerts:
Gentoo 201701-46 nss 2017-01-19
Gentoo 201512-10 firefox 2015-12-30
Oracle ELSA-2016-0685 nss, nspr, nss-softokn, and nss-util 2016-04-25
Debian-LTS DLA-315-1 nss 2015-09-27
Scientific Linux SLSA-2015:1664-1 nss 2015-08-24
Oracle ELSA-2015-1664 nss 2015-08-24
CentOS CESA-2015:1664 nss 2015-08-24
Red Hat RHSA-2015:1664-01 nss 2015-08-24
Debian DSA-3336-1 nss 2015-08-17
Debian DSA-3324-1 icedove 2015-08-01
CentOS CESA-2015:1699 nss-softokn 2015-09-01
Red Hat RHSA-2015:1699-01 nss-softokn 2015-09-01
CentOS CESA-2015:1699 nss-softokn 2015-09-01
Oracle ELSA-2015-1699 nss-softokn 2015-09-01
SUSE SUSE-SU-2015:1449-1 MozillaFirefox, mozilla-nss 2015-08-28
Ubuntu USN-2673-1 thunderbird 2015-07-20
SUSE SUSE-SU-2015:1268-2 firefox, nspr, nss 2015-07-20
SUSE SUSE-SU-2015:1268-1 firefox, nspr, nss 2015-07-20
SUSE SUSE-SU-2015:1269-1 firefox, nspr, nss 2015-07-20
openSUSE openSUSE-SU-2015:1266-1 firefox, thunderbird 2015-07-18
Scientific Linux SLSA-2015:1699-1 nss-softokn 2015-09-01
Oracle ELSA-2015-1699 nss-softokn 2015-09-01
Ubuntu USN-2656-2 firefox 2015-07-15
openSUSE openSUSE-SU-2015:1229-1 Firefox, nss 2015-07-13
Ubuntu USN-2672-1 nss 2015-07-09
Ubuntu USN-2656-1 firefox 2015-07-09
Mageia MGASA-2015-0268 firefox 2015-07-05

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds