Oracle Linux 7 : nss, / nss-softokn, / nss-util, / and / nspr (ELSA-2019-2237)

medium Nessus Plugin ID 180759

Synopsis

The remote Oracle Linux host is missing one or more security updates.

Description

The remote Oracle Linux 7 host has packages installed that are affected by multiple vulnerabilities as referenced in the ELSA-2019-2237 advisory.

nspr [4.21.0-1]
- Rebase to NSPR 4.21

nss [3.44.0-4]
- Fix certutil man page
- Fix extracting a public key from a private key for dh, ec, and dsa

[3.44.0-3]
- Disable TLS 1.3 under FIPS mode
- Disable RSASSA-PKCS1-v1_5 in TLS 1.3
- Fix post-handshake auth transcript calculation if SSL_ENABLE_SESSION_TICKETS is set

[3.44.0-2]
- Skip sysinit gtests properly
- Fix shell syntax error in tests/ssl/ssl.sh
- Regenerate manual pages

[3.44.0-1]
- Rebase to NSS 3.44
- Restore fix-min-library-version-in-SSLVersionRange.patch to keep SSL3 supported in the code level while it is disabled by policy
- Skip TLS 1.3 tests under FIPS mode

[3.43.0-9]
- Ignore system policy when running %check

[3.43.0-8]
- Fix policy string

[3.43.0-7]
- Dont override date in man-pages
- Revert the change to use XDG basedirs (mozilla#818686)
- Enable SSL2 compatible ClientHello by default
- Disable SSL3 and RC4 by default

[3.43.0-6]
- Make '-V ssl3:' option work with tools

[3.43.0-5]
- Fix regression in MD5 disablement

[3.43.0-4]
- add certutil documentation

[3.43.0-3]
- Restore complete removal of SSLv2
- Disable SSLv3
- Move signtool to unsupported directory

[3.43.0-2]
- Expand IPSEC usage to include ssl and email certs. Remove special processing of the usage based on the critical flag

[3.43.0-1]
- Rebase to NSS 3.43

[3.36.0-8.1]
- move key on unwrap failure and retry.

[3.36.0-8]
- Update the cert verify code to allow a new ipsec usage and follow RFC 4945

nss-softokn [3.44.0-5.0.1]
- Add fips140-2 DSA Known Answer Test fix [Orabug: 26679337]
- Add fips140-2 ECDSA/RSA/DSA Pairwise Consistency Test fix [Orabug: 26617814], [Orabug: 26617879], [Orabug: 26617849]

[3.44.0-5]
- Add pub from priv mechanism

[3.44.0-4]
- Add ike mechanisms
- FIPS update

[3.44.0-3]
- Remove stray 'exit' in %prep

[3.44.0-2]
- Fix nss-softokn-fs-probe.patch to detect threshold correctly

[3.44.0-1]
- Rebase to NSS 3.44

[3.43.0-5]
- Restore nss-softokn-fs-probe.patch

[3.43.0-4]
- Enable iquote.patch

[3.43.0-2]
- Rebuild

nss-util [3.44.0-3]
- Add pub from priv mechanism
- ike mechanisms should not overlap with JPAKE

[3.44.0-2]
- Add ike mechanisms

[3.44.0-1]
- Rebase to NSS 3.44

[3.43.0-1]
- Rebase to NSS 3.43

[3.36.0-2]
- Update the cert verify code to allow a new ipsec usage and follow RFC 4945

Tenable has extracted the preceding description block directly from the Oracle Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://linux.oracle.com/errata/ELSA-2019-2237.html

Plugin Details

Severity: Medium

ID: 180759

File Name: oraclelinux_ELSA-2019-2237.nasl

Version: 1.2

Type: local

Agent: unix

Published: 9/7/2023

Updated: 11/1/2024

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.4

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2018-12404

CVSS v3

Risk Factor: Medium

Base Score: 5.9

Temporal Score: 5.3

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:oracle:linux:nss-softokn-freebl-devel, p-cpe:/a:oracle:linux:nss-util, p-cpe:/a:oracle:linux:nss-softokn-freebl, p-cpe:/a:oracle:linux:nss-softokn, cpe:/o:oracle:linux:7, p-cpe:/a:oracle:linux:nss-pkcs11-devel, p-cpe:/a:oracle:linux:nspr, p-cpe:/a:oracle:linux:nspr-devel, p-cpe:/a:oracle:linux:nss-softokn-devel, p-cpe:/a:oracle:linux:nss-sysinit, p-cpe:/a:oracle:linux:nss-devel, p-cpe:/a:oracle:linux:nss-util-devel, p-cpe:/a:oracle:linux:nss-tools, p-cpe:/a:oracle:linux:nss

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/OracleLinux

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/13/2019

Vulnerability Publication Date: 6/13/2018

Reference Information

CVE: CVE-2018-0495, CVE-2018-12404