SuSE: 2014:1220-3: important: mozilla-nss
Summary
Mozilla NSS was updated to version 3.16.5 to fix a RSA certificate forgery
issue.
MFSA 2014-73 / CVE-2014-1568: Antoine Delignat-Lavaud, security researcher
at Inria Paris in team Prosecco, reported an issue in Network Security
Services (NSS) libraries affecting all versions. He discovered that NSS is
vulnerable to a variant of a signature forgery attack previously published
by Daniel Bleichenbacher. This is due to lenient parsing of ASN.1 values
involved in a signature and could lead to the forging of RSA certificates.
The Advanced Threat Research team at Intel Security also independently
discovered and reported this issue.
Security Issues:
* CVE-2014-1568
References
#897890
Cross- CVE-2014-1568
Affected Products:
SUSE Linux Enterprise Server 11 SP1 LTSS
SUSE Linux Enterprise Server 10 SP3 LTSS
https://www.suse.com/security/cve/CVE-2014-1568.html
https://bugzilla.suse.com/show_bug.cgi?id=897890
https://scc.suse.com:443/patches/
https://scc.suse.com:443/patches/