Allocation of Resources Without Limits or Throttling in Mozilla NSS - CVE-2020-25648

 

Allocation of Resources Without Limits or Throttling in Mozilla NSS - CVE-2020-25648

Published: October 21, 2020 / Updated: October 26, 2020


Vulnerability identifier: #VU47910
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-25648
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.


Affected software

Mozilla NSS
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Ubuntu
openEuler
Fedora
Red Hat OpenShift GitOps
Migration Toolkit for Containers
Cloud Pak for Security (CP4S)
Red Hat Advanced Cluster Management for Kubernetes
nss (Alpine package)
nss (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libnss3 (Ubuntu package)
nss-util
nss-util-devel
nss-debuginfo
nss-devel
nss-softokn
nss-help
nss-softokn-devel
nss-debugsource
nss
dev-libs/nss
nspr
nspr-devel
nspr (Red Hat package)
Oracle Communications Offline Mediation Controller
Oracle Communications Pricing Design Center
OpenShift Virtualization

How to mitigate CVE-2020-25648

Install update from vendor's website.

Migration Toolkit for Containers - update to 1.4.6
Cloud Pak for Security (CP4S) - update to 1.8.0.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.3.3
nss (Red Hat package) - addressed in versions 3.53.1-7.el7_9, 3.67.0-6.el8_4
OpenShift Virtualization - addressed in versions 2.6.8, 4.9.0
libnss3 (Ubuntu package) - addressed in versions 2:3.35-2ubuntu2.14, 2:3.49.1-1ubuntu1.7
nss-util - update to 3.54.0-6
nss-util-devel - update to 3.54.0-6
nss-debuginfo - update to 3.54.0-6
nss-devel - update to 3.54.0-6
nss-softokn - update to 3.54.0-6
nss-help - update to 3.54.0-6
nss-softokn-devel - update to 3.54.0-6
nss-debugsource - update to 3.54.0-6
nss - update to 3.54.0-6
dev-libs/nss - update to 3.58
nss - addressed in versions 3.58.0-3.fc31, 3.58.0-3.fc32, 3.58.0-3.fc33
nspr - update to 4.32.0-1
nspr-devel - update to 4.32.0-1
nspr (Red Hat package) - update to 4.32.0-1.el8_4

External References

Related Security Bulletins