SuSE 10 Security Update : mozilla-nss (ZYPP Patch Number 7842) (BEAST)

critical Nessus Plugin ID 57226

Synopsis

The remote SuSE 10 host is missing a security-related patch.

Description

This update to version 3.13.1 of mozilla-nss fixes the following issues :

- Explicitly distrust DigiCert Sdn. Bhd (bmo#698753)

- Better SHA-224 support (bmo#647706)

- Fix a regression (causing hangs in some situations) introduced in 3.13 (bmo#693228)

- SSL 2.0 is disabled by default

- A defense against the SSL 3.0 and TLS 1.0 CBC chosen plaintext attack demonstrated by Rizzo and Duong (CVE-2011-3389) has been enabled by default. Set the SSL_CBC_RANDOM_IV SSL option to PR_FALSE to disable it.

- Support SHA-224

- Add PORT_ErrorToString and PORT_ErrorToName to return the error message and symbolic name of an NSS error code

- Add NSS_GetVersion to return the NSS version string

- Add experimental support of RSA-PSS to the softoken only

- NSS_NoDB_Init does not try to open /pkcs11.txt and /secmod.db anymore (bmo#641052)

Solution

Apply ZYPP patch number 7842.

See Also

http://support.novell.com/security/cve/CVE-2011-2372.html

http://support.novell.com/security/cve/CVE-2011-2996.html

http://support.novell.com/security/cve/CVE-2011-2998.html

http://support.novell.com/security/cve/CVE-2011-2999.html

http://support.novell.com/security/cve/CVE-2011-3000.html

http://support.novell.com/security/cve/CVE-2011-3001.html

http://support.novell.com/security/cve/CVE-2011-3389.html

http://support.novell.com/security/cve/CVE-2011-3647.html

http://support.novell.com/security/cve/CVE-2011-3648.html

http://support.novell.com/security/cve/CVE-2011-3649.html

http://support.novell.com/security/cve/CVE-2011-3650.html

http://support.novell.com/security/cve/CVE-2011-3651.html

http://support.novell.com/security/cve/CVE-2011-3653.html

http://support.novell.com/security/cve/CVE-2011-3655.html

Plugin Details

Severity: Critical

ID: 57226

File Name: suse_mozilla-nss-7842.nasl

Version: 1.13

Type: local

Agent: unix

Published: 12/13/2011

Updated: 12/5/2022

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/o:suse:suse_linux

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Patch Publication Date: 11/16/2011

Vulnerability Publication Date: 9/6/2011

Reference Information

CVE: CVE-2011-2372, CVE-2011-2996, CVE-2011-2998, CVE-2011-2999, CVE-2011-3000, CVE-2011-3001, CVE-2011-3389, CVE-2011-3647, CVE-2011-3648, CVE-2011-3649, CVE-2011-3650, CVE-2011-3651, CVE-2011-3653, CVE-2011-3655