nss-3.36.0-9.AXS4
エラータID: AXSA:2018-3352:01
Network Security Services (NSS) is a set of libraries designed to support the cross-platform development of security-enabled client and server applications.
Security Fix(es):
* nss: ServerHello.random is all zeros when handling a v2-compatible ClientHello (CVE-2018-12384)
For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Asianux would like to thank the Mozilla project for reporting this issue.
CVE-2018-12384
** RESERVED **
This candidate has been reserved by an organization or individual that
will use it when announcing a new security problem. When the
candidate has been publicized, the details for this candidate will be provided.
Update packages.
When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead. This results in full malleability of the ClientHello for SSLv2 used for TLS 1.2 in all versions prior to NSS 3.39. This does not impact TLS 1.3.
N/A
SRPMS
- nss-3.36.0-9.AXS4.src.rpm
MD5: 5cec60772cd4be207573ded1ddca6f14
SHA-256: 3623b929d5c730ecb8acc8e226fa0e534ae39f0d8c13dd07a247dc70a86e4898
Size: 22.31 MB
Asianux Server 4 for x86
- nss-3.36.0-9.AXS4.i686.rpm
MD5: 8652262c7ad2a69969b1b082ded62a18
SHA-256: 962cf81fb0824cd7389bfee7486a407aed22430cd0a393164a71c9d36e5e442e
Size: 870.92 kB - nss-devel-3.36.0-9.AXS4.i686.rpm
MD5: 782a417806e8a8a3e406ac446a8edf74
SHA-256: 41db3c88cf477433e7576b857d3f7807a92a43f7b09a0144085ffbe39763fbed
Size: 221.96 kB - nss-sysinit-3.36.0-9.AXS4.i686.rpm
MD5: bf072ea57b928dd9a3f16393f46d41d9
SHA-256: 774d5e11effb8bccae29842fc9fa93fb287b45f882ab6df8e1c670c3279664b9
Size: 52.17 kB - nss-tools-3.36.0-9.AXS4.i686.rpm
MD5: 3e2cd504336997fc7352bdc642efe959
SHA-256: 59d5038efbd88d881cd57e30ea6bce09a1406fe4fb9d4144642adaaea330f202
Size: 467.99 kB
Asianux Server 4 for x86_64
- nss-3.36.0-9.AXS4.x86_64.rpm
MD5: 02618fb45b2835cd681656646ce1d3de
SHA-256: 3359b355143fc341e2688143d99b4dc7744e5773695f880068a6eed5a286a379
Size: 864.48 kB - nss-devel-3.36.0-9.AXS4.x86_64.rpm
MD5: 52eb4a3e6dc62fda1558e2628d35b085
SHA-256: 1fd9257674eb78aeb63b4ff6969fa71e50c89ea7ee1fc3c7c488c6b971c2e4eb
Size: 220.10 kB - nss-sysinit-3.36.0-9.AXS4.x86_64.rpm
MD5: 4d471dcbf7e7d9ea58f38d4d9f942643
SHA-256: 73ee292a3f4c47490230bca727f648db8d6f201ca30826911eea2c71ccfd86bb
Size: 51.79 kB - nss-tools-3.36.0-9.AXS4.x86_64.rpm
MD5: e220afc72c924ce6b6698e3e49b6f4c5
SHA-256: ff7812585328c38b80f2f18411ad96b45744ae7c903dd61709d28a3e6f736e0b
Size: 459.21 kB - nss-3.36.0-9.AXS4.i686.rpm
MD5: 8652262c7ad2a69969b1b082ded62a18
SHA-256: 962cf81fb0824cd7389bfee7486a407aed22430cd0a393164a71c9d36e5e442e
Size: 870.92 kB - nss-devel-3.36.0-9.AXS4.i686.rpm
MD5: 782a417806e8a8a3e406ac446a8edf74
SHA-256: 41db3c88cf477433e7576b857d3f7807a92a43f7b09a0144085ffbe39763fbed
Size: 221.96 kB