Summary: | <dev-libs/nss-3.14.3: TLS CBC padding timing attack (CVE-2013-1620) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | mozilla |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bugzilla.redhat.com/show_bug.cgi?id=907589 | ||
Whiteboard: | A3 [glsa] | ||
Package list: | Runtime testing required: | --- |
Description
Agostino Sarubbo
![]() dev-libs/nss-3.14.2 is in the tree now. Dunno if that contains a fix for this problem though. (In reply to comment #1) > dev-libs/nss-3.14.2 is in the tree now. Dunno if that contains a fix for > this problem though. No it does not contain the fix, I am adding 3.14.3 to tree in next couple of minutes which does tho :) Feel free to bring in the archs, nss-3.14.3 is now in the tree. (In reply to comment #3) > Feel free to bring in the archs, nss-3.14.3 is now in the tree. Thanks, Jory. Arches, please test and mark stable The following keyword changes are necessary to proceed: (see "package.accept_keywords" in the portage(5) man page for more details) #required by dev-libs/nss-3.14.3, required by =dev-libs/nss-3.14.3 (argument) =dev-libs/nspr-4.9.5 ~x86 Any objection in getting that one stable as well? amd64 stable x86 stable ppc stable ppc64 stable ia64 stable hppa stable sparc stable arm stable alpha stable CVE-2013-1620 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1620): The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169. Added to existing GLSA request. This issue was resolved and addressed in GLSA 201406-19 at http://security.gentoo.org/glsa/glsa-201406-19.xml by GLSA coordinator Mikle Kolyada (Zlogene). |