Inicial ▼ Bookkeeping
Online ▼ Auditorias ▼
DNS
Administrado ▼
Acerca de DNS
Ordenar/Renovar
Preguntas Frecuentes
AUP
Dynamic DNS Clients
Configurar Dominios Dynamic DNS Update Password Monitoreo
de Redes ▼
Enterprise
Avanzado
Estándarr
Prueba
Preguntas Frecuentes
Resumen de Precio/Funciones
Ordenar
Muestras
Configure/Status Alert Profiles | |||
ID de Prueba: | 1.3.6.1.4.1.25623.1.0.892388 |
Categoría: | Debian Local Security Checks |
Título: | Debian LTS: Security Advisory for nss (DLA-2388-1) |
Resumen: | The remote host is missing an update for the 'nss'; package(s) announced via the DLA-2388-1 advisory. |
Descripción: | Summary: The remote host is missing an update for the 'nss' package(s) announced via the DLA-2388-1 advisory. Vulnerability Insight: Various vulnerabilities were fixed in nss, the Network Security Service libraries. CVE-2018-12404 Cache side-channel variant of the Bleichenbacher attack. CVE-2018-18508 NULL pointer dereference in several CMS functions resulting in a denial of service. CVE-2019-11719 Out-of-bounds read when importing curve25519 private key. CVE-2019-11729 Empty or malformed p256-ECDH public keys may trigger a segmentation fault. CVE-2019-11745 Out-of-bounds write when encrypting with a block cipher. CVE-2019-17006 Some cryptographic primitives did not check the length of the input text, potentially resulting in overflows. CVE-2019-17007 Handling of Netscape Certificate Sequences may crash with a NULL dereference leading to a denial of service. CVE-2020-12399 Force a fixed length for DSA exponentiation. CVE-2020-6829 CVE-2020-12400 Side channel attack on ECDSA signature generation. CVE-2020-12401 ECDSA timing attack mitigation bypass. CVE-2020-12402 Side channel vulnerabilities during RSA key generation. CVE-2020-12403 CHACHA20-POLY1305 decryption with undersized tag leads to out-of-bounds read. Affected Software/OS: 'nss' package(s) on Debian Linux. Solution: For Debian 9 stretch, these problems have been fixed in version 2:3.26.2-1.1+deb9u2. We recommend that you upgrade your nss packages. CVSS Score: 10.0 CVSS Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C |
Referencia Cruzada: |
Common Vulnerability Exposure (CVE) ID: CVE-2020-6829 https://bugzilla.mozilla.org/show_bug.cgi?id=1631583 https://www.mozilla.org/security/advisories/mfsa2020-36/ https://www.mozilla.org/security/advisories/mfsa2020-39/ |
Copyright | Copyright (C) 2020 Greenbone Networks GmbH |
Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa. Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora. |