Описание
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 2:3.35-2ubuntu2.14 |
| devel | not-affected | 3.61-1ubuntu2 |
| esm-infra-legacy/trusty | not-affected | code not present |
| esm-infra/bionic | released | 2:3.35-2ubuntu2.14 |
| esm-infra/focal | released | 2:3.49.1-1ubuntu1.7 |
| esm-infra/xenial | not-affected | code not present |
| focal | released | 2:3.49.1-1ubuntu1.7 |
| groovy | ignored | end of life |
| hirsute | not-affected | 3.61-1ubuntu2 |
| impish | not-affected | 3.61-1ubuntu2 |
Показывать по
5 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) message ...
Moderate: nss and nspr security, bug fix, and enhancement update
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.
5 Medium
CVSS2
7.5 High
CVSS3