[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2013-216 ---- nspr

ID: oval:org.secpod.oval:def:1600325Date: (C)2016-05-19   (M)2023-12-07
Class: PATCHFamily: unix




It was discovered that NSS leaked timing information when decrypting TLS/SSL and DTLS protocol encrypted records when CBC-mode cipher suites were used. A remote attacker could possibly use this flaw to retrieve plain text from the encrypted packets by using a TLS/SSL or DTLS server as a padding oracle. An out-of-bounds memory read flaw was found in the way NSS decoded certain certificates. If an application using NSS decoded a malformed certificate, it could cause the application to crash

Platform:
Amazon Linux AMI
Product:
nspr
Reference:
ALAS-2013-216
CVE-2013-0791
CVE-2013-1620
CVE    2
CVE-2013-1620
CVE-2013-0791
CPE    2
cpe:/o:amazon:linux
cpe:/a:mozilla:netscape_portable_runtime

© SecPod Technologies