desktop-packages team mailing list archive
-
desktop-packages team
-
Mailing list archive
-
Message #127771
[Bug 1465014] Re: Firefox and Chromium still vulnerable against LOGJAM
This bug was fixed in the package nss 2:3.19.2-0ubuntu15.04.1
---
nss (2:3.19.2-0ubuntu15.04.1) vivid-security; urgency=medium
* SECURITY UPDATE: update to upstream 3.19.2 to fix multiple security
issues and get a new CA certificate bundle.
- CVE-2015-2721
- CVE-2015-2730
* debian/libnss3.symbols: updated for new version.
* debian/patches/relax_dh_size.patch: relax minimum DH size to 768 bits
for compatibility reasons. This patch will get reverted in the future
once servers have upgraded to longer DH sizes.
-- Marc Deslauriers <marc.deslauriers@xxxxxxxxxx> Wed, 08 Jul 2015
11:27:56 -0400
** Changed in: nss (Ubuntu)
Status: Triaged => Fix Released
--
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to firefox in Ubuntu.
https://bugs.launchpad.net/bugs/1465014
Title:
Firefox and Chromium still vulnerable against LOGJAM
Status in Network Security Services (NSS):
Fix Released
Status in firefox package in Ubuntu:
Fix Released
Status in nss package in Ubuntu:
Fix Released
Bug description:
Hint: http://www.ubuntu.com/usn/usn-2639-1/
" As a security improvement, this update also modifies OpenSSL
behaviour to reject DH key sizes below 768 bits, preventing a possible
downgrade attack. "
I installed the update but the test site says, i'm still vulnerable (see attachted screen shot).
Site: https://weakdh.org/
- Xubuntu 15.04 -- up-to-date
- openSSL 1.0.1f-1ubuntu11.4 -- up-to-date
- Firefox 38.0+build3-0ubuntu0.15.04.1 -- up-to-date (even there are the versions 38.0.5 and 38.0.6 on the mozilla server available)
- Chromium 43.0.2357.81-0ubuntu0.15.04.1.1170 -- up-to-date
--------------------------------------------------------------------------------
ProblemType: Bug
DistroRelease: Ubuntu 15.04
Package: openssl 1.0.1f-1ubuntu11.4
ProcVersionSignature: Ubuntu 3.19.0-20.20-generic 3.19.8
Uname: Linux 3.19.0-20-generic x86_64
ApportVersion: 2.17.2-0ubuntu1.1
Architecture: amd64
Date: Sun Jun 14 15:34:46 2015
InstallationDate: Installed on 2015-05-28 (16 days ago)
InstallationMedia: Xubuntu 15.04 "Vivid Vervet" - Release amd64 (20150422.1)
SourcePackage: openssl
UpgradeStatus: No upgrade log present (probably fresh install)
To manage notifications about this bug go to:
https://bugs.launchpad.net/nss/+bug/1465014/+subscriptions