SB2018100241 - Man-in-the-middle attack in nss (Alpine package)
Published: October 2, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Man-in-the-middle attack (CVE-ID: CVE-2018-12384)
The vulnerability allows a remote attacker to conduct man-in-the-middle attack on the target system.
The weakness exists due to ServerHello.random is all zero when handling a v2-compatible ClientHello. A remote attacker can use man-in-the-middle techniques to conduct passive replay attack and obtain potentially sensitive information.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=1cf2a95d5e12256524f77e43497146c98ea1cec2
- https://git.alpinelinux.org/aports/commit/?id=10d9b859f21c3a2b7db4ec0d764cba419f4dfc4b
- https://git.alpinelinux.org/aports/commit/?id=447318e4bff01df5d8424ebddea8345bd4a29501
- https://git.alpinelinux.org/aports/commit/?id=d72dda5f6aca3e285cc381ec3b01d1925d92f976