MGASA-2014-0507

Source
https://advisories.mageia.org/MGASA-2014-0507.html
Import Source
https://advisories.mageia.org/MGASA-2014-0507.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0507
Related
  • CVE-2014-1569
  • CVE-2014-1587
  • CVE-2014-1590
  • CVE-2014-1592
  • CVE-2014-1593
  • CVE-2014-1594
Published
2014-12-03T19:27:32Z
Modified
2014-12-03T19:18:54Z
Summary
Updated firefox & thunderbird packages fix security vulnerabilities
Details

Updated nss, firefox, and thunderbird packages fix security vulnerabilities:

In the QuickDER decoder in NSS before 3.17.3, ASN.1 DER decoding of lengths is too permissive, allowing undetected smuggling of arbitrary data (CVE-2014-1569).

Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox or Thunderbird to crash or, potentially, execute arbitrary code with the privileges of the user running it (CVE-2014-1587, CVE-2014-1590, CVE-2014-1592, CVE-2014-1593).

A flaw was found in the Alarm API, which could allow applications to schedule actions to be run in the future. A malicious web application could use this flaw to bypass the same-origin policy (CVE-2014-1594).

This update adds support for the TLS Fallback Signaling Cipher Suite Value (TLSFALLBACKSCSV) in NSS, which can be used to prevent protocol downgrade attacks against applications which re-connect using a lower SSL/TLS protocol version when the initial connection indicating the highest supported protocol version fails. This can prevent a forceful downgrade of the communication to SSL 3.0, mitigating CVE-2014-3566, also known as POODLE. SSL 3.0 support has also been disabled by default in this Firefox and Thunderbird update, further mitigating POODLE.

References
Credits

Affected packages

Mageia:4 / rootcerts

Package

Name
rootcerts
Purl
pkg:rpm/mageia/rootcerts?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20141117.00-1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / nss

Package

Name
nss
Purl
pkg:rpm/mageia/nss?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.17.3-1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / firefox

Package

Name
firefox
Purl
pkg:rpm/mageia/firefox?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
31.3.0-1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / firefox-l10n

Package

Name
firefox-l10n
Purl
pkg:rpm/mageia/firefox-l10n?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
31.3.0-1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / thunderbird

Package

Name
thunderbird
Purl
pkg:rpm/mageia/thunderbird?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
31.3.0-1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / thunderbird-l10n

Package

Name
thunderbird-l10n
Purl
pkg:rpm/mageia/thunderbird-l10n?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
31.3.0-1.mga4

Ecosystem specific

{
    "section": "core"
}