PT-2018-1955 · Mozilla+5 · Network Security Services+5

Mt

·

Published

2018-08-14

·

Updated

2024-06-15

·

CVE-2018-12384

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Network Security Services (NSS) versions prior to 3.39
Description The issue is related to errors in generating values when handling SSLv2-compatible ClientHello requests, allowing for the full malleability of the ClientHello for SSLv2 used for TLS 1.2. This can enable a remote attacker to gain unauthorized access to protected information, potentially compromising the confidentiality and integrity of the data. The vulnerability does not impact TLS 1.3.
Recommendations For versions prior to 3.39, update to version 3.39 or later to resolve the issue. As a temporary workaround, consider restricting the use of SSLv2-compatible ClientHello requests until a patch is available.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2296
BDU:2018-01562
BDU:2019-01764
BDU:2019-04362
CESA-2018_2768
CESA-2018_2898
CVE-2018-12384
MGASA-2018-0393
OPENSUSE-SU-2018_4117-1
OPENSUSE-SU-2024:11058-1
RHSA-2018:2768
RHSA-2018:2898
RHSA-2018_2768
RHSA-2018_2898
SUSE-SU-2018:4235-1
SUSE-SU-2018:4236-1
SUSE-SU-2018:4236-2
USN-3850-1
USN-3850-2

Affected Products

Alt Linux
Centos
Network Security Services
Red Hat
Suse
Ubuntu