CVE-2015-2721
published 2015-07-06CVE-2015-2721: Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
3.28%
87.1th percentile
Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS state machine, which allows man-in-the-middle attackers to defeat cryptographic protection mechanisms by blocking messages, as demonstrated by removing a forward-secrecy property by blocking a ServerKeyExchange message, aka a "SMACK SKIP-TLS" issue.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | nss | < nss 2:3.19.1-1 (bookworm) | nss 2:3.19.1-1 (bookworm) |
| mozilla | firefox | >= 0 < 39.0+build5-0ubuntu0.14.04.1 | 39.0+build5-0ubuntu0.14.04.1 |
| mozilla | network_security_services | — | — |
| mozilla | nss | >= 0 < 2:3.19.1-1 | 2:3.19.1-1 |
| mozilla | nss | >= 0 < 2:3.19.1-1 | 2:3.19.1-1 |
| mozilla | nss | >= 0 < 2:3.19.1-1 | 2:3.19.1-1 |
| mozilla | nss | >= 0 < 2:3.19.1-1 | 2:3.19.1-1 |
| mozilla | nss | >= 0 < 2:3.19.2-0ubuntu0.14.04.1 | 2:3.19.2-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:31.8.0+build1-0ubuntu0.14.04.1 | 1:31.8.0+build1-0ubuntu0.14.04.1 |
| novell | suse_linux_enterprise_desktop | — | — |
| novell | suse_linux_enterprise_server | — | — |
| novell | suse_linux_enterprise_server | — | — |
| novell | suse_linux_enterprise_software_development_kit | — | — |
| oracle | solaris | — | — |
| oracle | vm_server | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fhwj-6xh8-h4rw: Mozilla Network Security Services (NSS) before 3
ghsa_unreviewed·2022-05-14
CVE-2015-2721 [MEDIUM] GHSA-fhwj-6xh8-h4rw: Mozilla Network Security Services (NSS) before 3
Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS state machine, which allows man-in-the-middle attackers to defeat cryptographic protection mechanisms by blocking messages, as demonstrated by removing a forward-secrecy property by blocking a ServerKeyExchange message, aka a "SMACK SKIP-TLS" issue.
OSV
thunderbird vulnerabilities
osv·2015-07-20·CVSS 4.3
CVE-2015-2721 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
Karthikeyan Bhargavan discovered that NSS incorrectly handled state
transitions for the TLS state machine. If a remote attacker were able to
perform a machine-in-the-middle attack, this flaw could be exploited to skip
the ServerKeyExchange message and remove the forward-secrecy property.
(CVE-2015-2721)
Bob Clary, Christian Holler, Bobby Holley, and Andrew McCreight discovered
multiple memory safety issues in Thunderbird. If a user were tricked in to
opening a specially crafted website in a browsing context, an attacker
could potentially exploit these to cause a denial of service via
application crash, or execute arbitrary code with the privileges of the
user invoking Thunderbird. (CVE-2015-2724)
Ronald Crane discovered multiple security vulnerabilities. If a
OSV
firefox vulnerabilities
osv·2015-07-09·CVSS 4.3
CVE-2015-2721 [MEDIUM] firefox vulnerabilities
firefox vulnerabilities
Karthikeyan Bhargavan discovered that NSS incorrectly handled state
transitions for the TLS state machine. If a remote attacker were able to
perform a machine-in-the-middle attack, this flaw could be exploited to skip
the ServerKeyExchange message and remove the forward-secrecy property.
(CVE-2015-2721)
Looben Yan discovered 2 use-after-free issues when using XMLHttpRequest in
some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking Firefox. (CVE-2015-2722,
CVE-2015-2733)
Bob Clary, Christian Holler, Bobby Holley, Andrew McCreight, Terrence
Cole, Steve Fink, Mats Palmgren, W
OSV
nss vulnerabilities
osv·2015-07-09·CVSS 4.3
CVE-2015-2721 [MEDIUM] nss vulnerabilities
nss vulnerabilities
Karthikeyan Bhargavan discovered that NSS incorrectly handled state
transitions for the TLS state machine. If a remote attacker were able to
perform a machine-in-the-middle attack, this flaw could be exploited to skip
the ServerKeyExchange message and remove the forward-secrecy property.
(CVE-2015-2721)
Watson Ladd discovered that NSS incorrectly handled Elliptical Curve
Cryptography (ECC) multiplication. A remote attacker could possibly use
this issue to spoof ECDSA signatures. (CVE-2015-2730)
As a security improvement, this update modifies NSS behaviour to reject DH
key sizes below 768 bits, preventing a possible downgrade attack.
This update also refreshes the NSS package to version 3.19.2 which includes
the latest CA certificate bundle.
OSV
CVE-2015-2721: Mozilla Network Security Services (NSS) before 3
osv·2015-07-06·CVSS 4.3
CVE-2015-2721 [MEDIUM] CVE-2015-2721: Mozilla Network Security Services (NSS) before 3
Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS state machine, which allows man-in-the-middle attackers to defeat cryptographic protection mechanisms by blocking messages, as demonstrated by removing a forward-secrecy property by blocking a ServerKeyExchange message, aka a "SMACK SKIP-TLS" issue.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2015-07-20·CVSS 4.3
CVE-2015-2721 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Karthikeyan Bhargavan discovered that NSS incorrectly handled state
transitions for the TLS state machine. If a remote attacker were able to
perform a machine-in-the-middle attack, this flaw could be exploited to skip
the ServerKeyExchange message and remove the forward-secrecy property.
(CVE-2015-2721)
Bob Clary, Christian Holler, Bobby Holley, and Andrew McCreight discovered
multiple memory safety issues in Thunderbird. If a user were tricked in to
opening a specially crafted website in a browsing context, an attacker
could potentially exploit these to cause a denial of service via
application crash, or execute arbitrary code with the privileges of the
user invoking Thunderbird. (CVE-2015-27
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2015-07-15·CVSS 4.3
CVE-2015-2721 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
USN-2656-1 fixed vulnerabilities in Firefox for Ubuntu 14.04 LTS and
later releases.
This update provides the corresponding update for Ubuntu 12.04 LTS.
Original advisory details:
Karthikeyan Bhargavan discovered that NSS incorrectly handled state
transitions for the TLS state machine. If a remote attacker were able to
perform a machine-in-the-middle attack, this flaw could be exploited to skip
the ServerKeyExchange message and remove the forward-secrecy property.
(CVE-2015-2721)
Looben Yan discovered 2 use-after-free issues when using XMLHttpRequest in
some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker c
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2015-07-09·CVSS 4.3
CVE-2015-2721 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Karthikeyan Bhargavan discovered that NSS incorrectly handled state
transitions for the TLS state machine. If a remote attacker were able to
perform a machine-in-the-middle attack, this flaw could be exploited to skip
the ServerKeyExchange message and remove the forward-secrecy property.
(CVE-2015-2721)
Looben Yan discovered 2 use-after-free issues when using XMLHttpRequest in
some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking Firefox. (CVE-2015-2722,
CVE-2015
Ubuntu
NSS vulnerabilities
vendor_ubuntu·2015-07-09·CVSS 4.3
CVE-2015-2721 [MEDIUM] NSS vulnerabilities
Title: NSS vulnerabilities
Summary: Several security issues were fixed in NSS.
Karthikeyan Bhargavan discovered that NSS incorrectly handled state
transitions for the TLS state machine. If a remote attacker were able to
perform a machine-in-the-middle attack, this flaw could be exploited to skip
the ServerKeyExchange message and remove the forward-secrecy property.
(CVE-2015-2721)
Watson Ladd discovered that NSS incorrectly handled Elliptical Curve
Cryptography (ECC) multiplication. A remote attacker could possibly use
this issue to spoof ECDSA signatures. (CVE-2015-2730)
As a security improvement, this update modifies NSS behaviour to reject DH
key sizes below 768 bits, preventing a possible downgrade attack.
This update also refreshes the NSS package to version 3.19.2 which includes
Red Hat
NSS: incorrectly permited skipping of ServerKeyExchange (MFSA 2015-71)
vendor_redhat·2015-07-02·CVSS 4.3
CVE-2015-2721 [MEDIUM] CWE-358 NSS: incorrectly permited skipping of ServerKeyExchange (MFSA 2015-71)
NSS: incorrectly permited skipping of ServerKeyExchange (MFSA 2015-71)
Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS state machine, which allows man-in-the-middle attackers to defeat cryptographic protection mechanisms by blocking messages, as demonstrated by removing a forward-secrecy property by blocking a ServerKeyExchange message, aka a "SMACK SKIP-TLS" issue.
It was found that NSS permitted skipping of the ServerKeyExchange packet during a handshake involving ECDHE (Elliptic Curve Diffie-Hellman key Exchange). A remote attacker could use this flaw to bypass the forward-secrecy of a TLS
Debian
CVE-2015-2721: nss - Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox ...
vendor_debian·2015·CVSS 4.3
CVE-2015-2721 [MEDIUM] CVE-2015-2721: nss - Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox ...
Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS state machine, which allows man-in-the-middle attackers to defeat cryptographic protection mechanisms by blocking messages, as demonstrated by removing a forward-secrecy property by blocking a ServerKeyExchange message, aka a "SMACK SKIP-TLS" issue.
Scope: local
bookworm: resolved (fixed in 2:3.19.1-1)
bullseye: resolved (fixed in 2:3.19.1-1)
forky: resolved (fixed in 2:3.19.1-1)
sid: resolved (fixed in 2:3.19.1-1)
trixie: resolved (fixed in 2:3.19.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-2721 NSS: incorrectly permited skipping of ServerKeyExchange (MFSA 2015-71)
bugzilla·2015-06-30·CVSS 4.3
CVE-2015-2721 [MEDIUM] CVE-2015-2721 NSS: incorrectly permited skipping of ServerKeyExchange (MFSA 2015-71)
CVE-2015-2721 NSS: incorrectly permited skipping of ServerKeyExchange (MFSA 2015-71)
Security researcher Karthikeyan Bhargavan reported an issue in Network Security Services (NSS) where the client allows for a ECDHE_ECDSA exchange where the server does not send its ServerKeyExchange message instead of aborting the handshake. Instead, the NSS client will take the EC key from the ECDSA certificate. This violates the TLS protocol and also has some security implications for forward secrecy. In this situation, the browser thinks it is engaged in an ECDHE exchange, but has been silently downgraded to a non-forward secret mixed-ECDH exchange instead. As a result, if False Start is enabled, the browser will start sending data encrypted under these non-forward-secret connection keys. This issue wa
Bugzilla
NSS accepts export-length DHE keys with regular DHE cipher suites ("Logjam")
bugzilla·2015-03-02
[MEDIUM] NSS accepts export-length DHE keys with regular DHE cipher suites ("Logjam")
NSS accepts export-length DHE keys with regular DHE cipher suites ("Logjam")
Discussion:
The following issue needs to be externally coordinated.
Matthew Green informed me this morning of a potential issue in libssl
and DHE processing. The scenario is a TLS server which is configured
for export DHE modes, such as:
TLS_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA
As well as stronger modes.
In this scenario, the server is supposed to use a 512-bit DHE key.
If the server uses a static key rather than a fresh key for each
connection, then it is potentially possible for an attacker to
break the key. At that point he modifies the client's ClientHello
to only offer the export DHE mode, causing the server to return
a valid ServerKeyExchange with that key. The attacker than computes
the master secret an
Bugzilla
NSS incorrectly permits skipping of ServerKeyExchange
bugzilla·2014-10-21
[MEDIUM] NSS incorrectly permits skipping of ServerKeyExchange
NSS incorrectly permits skipping of ServerKeyExchange
User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/38.0.2125.104 Safari/537.36
Steps to reproduce:
We have been performing systematic state machine tests on NSS, OpenSSL, and other SSL implementations, and we found some unexpected behaviours in NSS (not all are immediately exploitable.) We will report the other weirdnesses in due course, but here's one that seems to break False Start's forward secrecy guarantee.
The core issue is that the NSS client allows an ECDHE_ECDSA exchange where the server does not send its ServerKeyExchange message. In this case, NSS will take
the (long-term) EC key from the ECDSA certificate, and use that instead of the
server's ephemeral parameters. Thi
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1185.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1664.htmlhttp://www.debian.org/security/2015/dsa-3324http://www.debian.org/security/2015/dsa-3336http://www.mozilla.org/security/announce/2015/mfsa2015-71.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/75541http://www.securityfocus.com/bid/83398http://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1032783http://www.securitytracker.com/id/1032784http://www.ubuntu.com/usn/USN-2656-1http://www.ubuntu.com/usn/USN-2656-2http://www.ubuntu.com/usn/USN-2672-1http://www.ubuntu.com/usn/USN-2673-1https://bugzilla.mozilla.org/show_bug.cgi?id=1086145https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.19_release_noteshttps://security.gentoo.org/glsa/201512-10https://security.gentoo.org/glsa/201701-46https://smacktls.comhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-07/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1185.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1664.htmlhttp://www.debian.org/security/2015/dsa-3324http://www.debian.org/security/2015/dsa-3336http://www.mozilla.org/security/announce/2015/mfsa2015-71.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/75541http://www.securityfocus.com/bid/83398http://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1032783http://www.securitytracker.com/id/1032784http://www.ubuntu.com/usn/USN-2656-1http://www.ubuntu.com/usn/USN-2656-2http://www.ubuntu.com/usn/USN-2672-1http://www.ubuntu.com/usn/USN-2673-1https://bugzilla.mozilla.org/show_bug.cgi?id=1086145https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.19_release_noteshttps://security.gentoo.org/glsa/201512-10https://security.gentoo.org/glsa/201701-46https://smacktls.com
2015-07-06
Published