Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-2721

Опубликовано: 02 июл. 2015
Источник: redhat
CVSS2: 5.1
EPSS Низкий

Описание

Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS state machine, which allows man-in-the-middle attackers to defeat cryptographic protection mechanisms by blocking messages, as demonstrated by removing a forward-secrecy property by blocking a ServerKeyExchange message, aka a "SMACK SKIP-TLS" issue.

It was found that NSS permitted skipping of the ServerKeyExchange packet during a handshake involving ECDHE (Elliptic Curve Diffie-Hellman key Exchange). A remote attacker could use this flaw to bypass the forward-secrecy of a TLS/SSL connection.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gnutlsNot affected
Red Hat Enterprise Linux 5opensslNot affected
Red Hat Enterprise Linux 6gnutlsNot affected
Red Hat Enterprise Linux 6opensslNot affected
Red Hat Enterprise Linux 7gnutlsNot affected
Red Hat Enterprise Linux 7opensslNot affected
Red Hat Enterprise Linux 5nssFixedRHSA-2015:166424.08.2015
Red Hat Enterprise Linux 6nssFixedRHSA-2015:118525.06.2015
Red Hat Enterprise Linux 6nss-utilFixedRHSA-2015:118525.06.2015
Red Hat Enterprise Linux 7nssFixedRHSA-2015:118525.06.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-358
https://bugzilla.redhat.com/show_bug.cgi?id=1236967NSS: incorrectly permited skipping of ServerKeyExchange (MFSA 2015-71)

EPSS

Процентиль: 66%
0.00516
Низкий

5.1 Medium

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS state machine, which allows man-in-the-middle attackers to defeat cryptographic protection mechanisms by blocking messages, as demonstrated by removing a forward-secrecy property by blocking a ServerKeyExchange message, aka a "SMACK SKIP-TLS" issue.

nvd
около 10 лет назад

Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS state machine, which allows man-in-the-middle attackers to defeat cryptographic protection mechanisms by blocking messages, as demonstrated by removing a forward-secrecy property by blocking a ServerKeyExchange message, aka a "SMACK SKIP-TLS" issue.

debian
около 10 лет назад

Mozilla Network Security Services (NSS) before 3.19, as used in Mozill ...

github
больше 3 лет назад

Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS state machine, which allows man-in-the-middle attackers to defeat cryptographic protection mechanisms by blocking messages, as demonstrated by removing a forward-secrecy property by blocking a ServerKeyExchange message, aka a "SMACK SKIP-TLS" issue.

oracle-oval
около 10 лет назад

ELSA-2015-1664: nss security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 66%
0.00516
Низкий

5.1 Medium

CVSS2