Описание
The Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To mitigate this vulnerability, Firefox disabled support for DHE ciphersuites.
A flaw was found in Mozilla nss. A raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman(DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent over that TLS connection. The highest threat from this vulnerability is to data confidentiality.
Отчет
NSS as shipped with Red Hat Enterprise Linux 6, 7, and 8 does not re-use Diffie-Hellman Ephemeral (DHE) keys. It reuses Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) keys by default, but Attacking ECDH and ECDHE cipher suites are not in the scope of the Raccoon Attack and generally considered to be unaffected [1]. Further, reuse of ECDHE keys can be disabled starting in nss 3.17 [2]. For these reasons, Red Hat Product Security has marked the Severity of this flaw as Low. Please see [3] for more information about Low Severity ratings.
Меры по смягчению последствий
Any risk involving the ECDHE key reuse on the nss server can be mitigated by setting the SSL_REUSE_SERVER_ECDHE_KEY socket option to PR_FALSE.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | nss | Out of support scope | ||
| Red Hat Enterprise Linux 6 | nss | Out of support scope | ||
| Red Hat Enterprise Linux 7 | nss | Will not fix | ||
| Red Hat Enterprise Linux 8 | nss | Will not fix | ||
| Red Hat Enterprise Linux 9 | nss | Will not fix |
Показывать по
Дополнительная информация
Статус:
5.9 Medium
CVSS3
Связанные уязвимости
The Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To mitigate this vulnerability, Firefox disabled support for DHE ciphersuites.
The Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To mitigate this vulnerability, Firefox disabled support for DHE ciphersuites.
The Raccoon attack is a timing attack on DHE ciphersuites inherit in t ...
The Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To mitigate this vulnerability, Firefox disabled support for DHE ciphersuites.
5.9 Medium
CVSS3