Description
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3634-1 | nss security update |
EUVD |
EUVD-2020-18313 | A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58. |
Ubuntu USN |
USN-5410-1 | NSS vulnerability |
References
History
No history.
Subscriptions
Fedoraproject
Subscribe
Fedora
Subscribe
Mozilla
Subscribe
Network Security Services
Subscribe
Oracle
Subscribe
Communications Offline Mediation Controller
Subscribe
Communications Pricing Design Center
Subscribe
Jd Edwards Enterpriseone Tools
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Rhmt
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T15:40:36.481Z
Reserved: 2020-09-16T00:00:00.000Z
Link: CVE-2020-25648
No data.
Status : Modified
Published: 2020-10-20T22:15:43.217
Modified: 2024-11-21T05:18:20.080
Link: CVE-2020-25648
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN