please upgrade to 3.12.6

Bug #562332 reported by Jamie Strandboge
262
This bug affects 1 person
Affects Status Importance Assigned to Milestone
nss (Ubuntu)
Fix Released
Medium
Chris Coulson
Hardy
Fix Released
Medium
Unassigned
Intrepid
Invalid
Medium
Unassigned
Jaunty
Fix Released
Medium
Unassigned
Karmic
Fix Released
Medium
Chris Coulson
Lucid
Fix Released
Medium
Chris Coulson

Bug Description

3.12.6 fixes CVE-2009-3555.

NSS 3.12.6 has support for the new renegotiation extension for TLS to implement rfc5746. NSS clients advertise their support for this extension and if the server also supports it, will be protected from this vulnerability. To maintain compatibility, NSS in Ubuntu will for the foreseeable future use the so-called 'transitional' mode which will fall back to the unprotected renegotiation method if the server doesn't support the new extension.

NSS was fixed in Ubuntu 9.10 because the new Firefox required it. Because Firefox needs changes to take advantage of the new NSS, once Ubuntu 8.04 LTS - 9.04 are updated to use an embedded NSS (and therefore won't use the system NSS), we can update the system NSS for these releases.

When upgrading the system NSS on Ubuntu 8.04 LTS - 9.04, be careful about https://launchpad.net/bugs/559881 and https://launchpad.net/bugs/559918 (regressions seen with the 9.10 update).

visibility: private → public
Changed in nss (Ubuntu Lucid):
status: New → Fix Released
importance: Undecided → Medium
assignee: nobody → Chris Coulson (chrisccoulson)
Changed in nss (Ubuntu Karmic):
status: New → Fix Released
importance: Undecided → Medium
assignee: nobody → Chris Coulson (chrisccoulson)
Changed in nss (Ubuntu Hardy):
status: New → Triaged
importance: Undecided → Medium
Changed in nss (Ubuntu Intrepid):
status: New → Triaged
importance: Undecided → Medium
Changed in nss (Ubuntu Jaunty):
status: New → Triaged
importance: Undecided → Medium
Revision history for this message
Alex Valavanis (valavanisalex) wrote :

Intrepid Ibex reached end-of-life on 30 April 2010 so I am closing the
report. The bug has been fixed in newer releases of Ubuntu.

Changed in nss (Ubuntu Intrepid):
status: Triaged → Invalid
Changed in nss (Ubuntu Hardy):
status: Triaged → Fix Released
Changed in nss (Ubuntu Jaunty):
status: Triaged → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.