CVE-2015-7575
icedove - security update
5.9
MEDIUM
CVSS 3.1
EPSS 1.1%
Description
Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision.
How to fix CVE-2015-7575
To remediate CVE-2015-7575, upgrade the affected package to a fixed version below.
- —upgrade to 2.12.20-8+deb7u5 or later
- —upgrade to 3.3.15-1 or later
- —upgrade to 38.6.0-1~deb7u1 or later
- —upgrade to 38.6.0esr-1~deb7u1 or later
- —upgrade to 2:3.21-1 or later
- —upgrade to 6b38-1.13.10-1~deb6u1 or later
- —upgrade to 7u95-2.6.4-1~deb7u1 or later
- —upgrade to 1.0.1e-2+deb7u19 or later
- —upgrade to 1.0.1f-1 or later
Is CVE-2015-7575 being exploited?
Low — EPSS is 1.1%, meaning exploitation activity has not been observed at scale.
Affected packages (9)
- from 0, < 2.12.20-8+deb7u5
- from 0, < 3.3.15-1
- from 0, < 38.6.0-1~deb7u1
- from 0, < 38.6.0esr-1~deb7u1
- from 0, < 2:3.21-1
- from 0, < 6b38-1.13.10-1~deb6u1
- from 0, < 7u95-2.6.4-1~deb7u1
- from 0, < 1.0.1e-2+deb7u19
- from 0, < 1.0.1f-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |