PT-2015-2971 · Mozilla+7 · Network Security Services+10

Karthikeyan Bhargavan

·

Publicado

2015-12-22

·

Atualizado

2024-12-12

·

CVE-2015-7575

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 43.0.2 Mozilla Firefox ESR versions prior to 38.5.2 Mozilla Network Security Services (NSS) versions prior to 3.20.2 Oracle Java SE (affected versions not specified)
Description The issue is related to errors in the code of a security component, which can be exploited by a remote attacker to gain read, modify, add, or delete access to data using network packets. Specifically, the problem lies in the TLS 1.2 Handshake Protocol traffic, where MD5 signatures in Server Key Exchange messages are not rejected. This makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision, potentially allowing them to impersonate a TLS server and obtain credentials.
Recommendations For Mozilla Firefox versions prior to 43.0.2, update to version 43.0.2 or later to resolve the issue. For Mozilla Firefox ESR versions prior to 38.5.2, update to version 38.5.2 or later to resolve the issue. For Mozilla Network Security Services (NSS) versions prior to 3.20.2, update to version 3.20.2 or later to resolve the issue. For Oracle Java SE, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1012
ALT-PU-2016-1013
ALT-PU-2016-1454
BDU:2016-00136
CESA-2016_0007
CESA-2016_0008
CESA-2016_0012
CESA-2016_0049
CESA-2016_0050
CESA-2016_0053
CESA-2016_0054
CVE-2015-7575
DLA-410-1
DSA-3436-1
DSA-3437-1
DSA-3457-1
DSA-3458-1
DSA-3465-1
DSA-3491-1
DSA-3500-1
DSA-3688-1
MGASA-2016-0048
OPENSUSE-SU-2016_0263-1
OPENSUSE-SU-2016_0268-1
OPENSUSE-SU-2016_0270-1
OPENSUSE-SU-2016_0272-1
OPENSUSE-SU-2016_0279-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:10088-1
OPENSUSE-SU-2024:10197-1
OPENSUSE-SU-2024:10218-1
OPENSUSE-SU-2024:10230-1
OPENSUSE-SU-2024:10451-1
OPENSUSE-SU-2024:10486-1
OPENSUSE-SU-2024:10534-1
OPENSUSE-SU-2024:12903-1
OPENSUSE-SU-2024:14572-1
RHSA-2016:0007
RHSA-2016:0008
RHSA-2016:0012
RHSA-2016:0049
RHSA-2016:0050
RHSA-2016:0053
RHSA-2016:0054
RHSA-2016:0055
RHSA-2016:0056
RHSA-2016:0098
RHSA-2016:0099
RHSA-2016:0100
RHSA-2016:0101
RHSA-2016:1430
RHSA-2016_0007
RHSA-2016_0008
RHSA-2016_0012
RHSA-2016_0049
RHSA-2016_0050
RHSA-2016_0053
RHSA-2016_0054
RHSA-2016_0055
RHSA-2016_0056
RHSA-2016_0098
RHSA-2016_0099
RHSA-2016_0101
SUSE-SU-2016:0149-1
SUSE-SU-2016:0189-1
SUSE-SU-2016:0256-1
SUSE-SU-2016:0265-1
SUSE-SU-2016:0269-1
SUSE-SU-2016:0390-1
SUSE-SU-2016:0399-1
SUSE-SU-2016:0401-1
SUSE-SU-2016:0428-1
SUSE-SU-2016:0431-1
SUSE-SU-2016:0433-1
SUSE-SU-2016:0584-1
SUSE-SU-2016:0636-1
SUSE-SU-2016:0770-1
SUSE-SU-2016_0149-1
SUSE-SU-2016_0189-1
SUSE-SU-2016_0256-1
SUSE-SU-2016_0584-1
USN-2863-1
USN-2864-1
USN-2865-1
USN-2866-1
USN-2884-1
USN-2904-1

Produtos afetados

Alt Linux
Centos
Ibm Aix
Java Platform
Firefox
Firefox Esr
Network Security Services
Oracle Java Se
Red Hat
Suse
Ubuntu