Data Handling - CVE-2015-7575

 

Data Handling - CVE-2015-7575

Published: January 9, 2016 / Updated: August 4, 2020


Vulnerability identifier: #VU33638
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-7575
CWE-ID: CWE-19
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision.


Affected software

Amazon Linux AMI
Gentoo Linux
Fedora
IBM i
IBM BladeCenter Advanced Management Module
XIV Gen3
Integrated Management Module II (IMM2)
FlashSystem 840 9840-AE1 & 9843-AE1
Hyper-Scale Manager
XIV Management Tools
Content Manager Enterprise Edition
nss (Alpine package)
openssl101e
IBM BladeCenter 1/10Gb Uplink Ethernet Switch Module
IBM BladeCenter Virtual Fabric 10Gb Switch Module
IBM SAN Volume Controller
IBM Storwize V7000
IBM Storwize V3500
IBM Storwize V5000
IBM Storwize V3700

How to mitigate CVE-2015-7575

Install update from vendor's website.

nss (Alpine package) - update to 3.19.2.1-r1
Integrated Management Module II (IMM2) - update to 1aoo70h-5.40
openssl101e - update to 1.0.1e-6.el5
FlashSystem 840 9840-AE1 & 9843-AE1 - update to 1.5.2.6-468.155
Hyper-Scale Manager - update to 1.9.1
XIV Management Tools - update to 4.8.0.1
IBM BladeCenter 1/10Gb Uplink Ethernet Switch Module - addressed in versions 6.8.24.0, 7.4.14.0
IBM BladeCenter Virtual Fabric 10Gb Switch Module - addressed in versions 6.8.24.0, 7.8.10.0
IBM SAN Volume Controller - addressed in versions 7.3.0.12, 7.4.0.7, 7.5.0.6, 7.6.0.3
IBM Storwize V7000 - addressed in versions 7.3.0.12, 7.4.0.7, 7.5.0.6, 7.6.0.3
IBM Storwize V3500 - addressed in versions 7.3.0.12, 7.4.0.7, 7.5.0.6, 7.6.0.3
IBM Storwize V5000 - addressed in versions 7.3.0.12, 7.4.0.7, 7.5.0.6, 7.6.0.3
IBM Storwize V3700 - addressed in versions 7.3.0.12, 7.4.0.7, 7.5.0.6, 7.6.0.3

External References

Related Security Bulletins