Algorithm Downgrade in Mozilla Firefox - CVE-2019-17023

 

Algorithm Downgrade in Mozilla Firefox - CVE-2019-17023

Published: January 7, 2020 / Updated: January 8, 2020


Vulnerability identifier: #VU24061
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-17023
CWE-ID: CWE-757
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists due to insecure negotiation After a HelloRetryRequest in Mozilla NSS that can lead to selection of a less secure protocol (e.g. TLS 1.2 or below) after the HelloRetryRequest TLS 1.3 is sent.


Affected software

Mozilla Firefox
Arch Linux
Amazon Linux AMI
Debian Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
CentOS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Slackware Linux
Ansible Automation Platform
firefox (Ubuntu package)
firefox (Alpine package)
nss (Debian package)
nss-util (Red Hat package)
nss (Red Hat package)
nss-softokn (Red Hat package)
nspr (Red Hat package)
Data Computing Appliance (DCA)
OpenShift Virtualization
Red Hat OpenShift Container Platform

How to mitigate CVE-2019-17023

Install updates from vendor's website.

Mozilla Firefox - update to 72.0
Ansible Automation Platform - addressed in versions 1.0, 1.1, 1.2.4
firefox (Ubuntu package) - addressed in versions 72.0.1+build1-0ubuntu0.16.04.1, 72.0.1+build1-0ubuntu0.18.04.1, 72.0.1+build1-0ubuntu0.19.04.1, 72.0.1+build1-0ubuntu0.19.10.1
firefox (Alpine package) - update to 72.0.1-r0
Data Computing Appliance (DCA) - addressed in versions Firmware tool 3H00, 4.2.1.0
OpenShift Virtualization - update to 2.4.2
nss (Debian package) - update to 2:3.42.1-1+deb10u3
nss-util (Red Hat package) - update to 3.53.1-1.el7_9
nss (Red Hat package) - addressed in versions 3.53.1-3.el7_9, 3.53.1-11.el8_2
nss-softokn (Red Hat package) - update to 3.53.1-6.el7_9
Red Hat OpenShift Container Platform - update to 4.3.40
nspr (Red Hat package) - addressed in versions 4.25.0-2.el7_9, 4.25.0-2.el8_2

External References

Related Security Bulletins