CVE-2018-12384
published 2019-04-29CVE-2018-12384: When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead. This results in full…
PriorityP429medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
1.50%
71.4th percentile
When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead. This results in full malleability of the ClientHello for SSLv2 used for TLS 1.2 in all versions prior to NSS 3.39. This does not impact TLS 1.3.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nss | < nss 2:3.39-1 (bookworm) | nss 2:3.39-1 (bookworm) |
| fasterxml | jackson-databind | >= 0 < 2.4.2-3ubuntu0.1~esm2 | 2.4.2-3ubuntu0.1~esm2 |
| mozilla | network_security_services | < 3.39 | 3.39 |
| mozilla | nss | >= 0 < 2:3.39-1 | 2:3.39-1 |
| mozilla | nss | >= 0 < 2:3.39-1 | 2:3.39-1 |
| mozilla | nss | >= 0 < 2:3.39-1 | 2:3.39-1 |
| mozilla | nss | >= 0 < 2:3.39-1 | 2:3.39-1 |
| mozilla | nss | >= 0 < 2:3.28.4-0ubuntu0.14.04.4 | 2:3.28.4-0ubuntu0.14.04.4 |
| mozilla | nss | >= 0 < 2:3.28.4-0ubuntu0.16.04.4 | 2:3.28.4-0ubuntu0.16.04.4 |
| mozilla | nss | >= 0 < 2:3.35-2ubuntu2.1 | 2:3.35-2ubuntu2.1 |
| nss | network_security_services | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
vendor_ubuntu4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rg3c-6wcj-37gm: When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead
ghsa_unreviewed·2022-05-24
CVE-2018-12384 [MEDIUM] CWE-335 GHSA-rg3c-6wcj-37gm: When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead
When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead. This results in full malleability of the ClientHello for SSLv2 used for TLS 1.2 in all versions prior to NSS 3.39. This does not impact TLS 1.3.
OSV
jackson-databind vulnerabilities
osv·2021-03-15·CVSS 9.8
CVE-2018-11307 jackson-databind vulnerabilities
jackson-databind vulnerabilities
It was discovered that Jackson Databind incorrectly handled
deserialization. An attacker could possibly use this issue to obtain
sensitive information. (CVE-2018-11307, CVE-2019-12086, CVE-2019-12814)
It was discovered that Jackson Databind incorrectly handled
deserialization. An attacker could possibly use this issue to execute
arbitrary code or other unspecified impact. (CVE-2018-12022,
CVE-2018-12023, CVE-2018-14718, CVE-2018-14719, CVE-2018-19360,
CVE-2018-19361, CVE-2018-19362, CVE-2019-12384, CVE-2019-14379,
CVE-2019-14439, CVE-2019-14540, CVE-2019-16335, CVE-2019-16942,
CVE-2019-16943, CVE-2019-17267, CVE-2019-17531, CVE-2019-20330,
CVE-2020-10672, CVE-2020-10673, CVE-2020-10968, CVE-2020-10969,
CVE-2020-11111, CVE-2020-11112, CVE-2020-11113, CVE-2
OSV
CVE-2018-12384: When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead
osv·2019-04-29·CVSS 5.9
CVE-2018-12384 [MEDIUM] CVE-2018-12384: When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead
When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead. This results in full malleability of the ClientHello for SSLv2 used for TLS 1.2 in all versions prior to NSS 3.39. This does not impact TLS 1.3.
OSV
nss vulnerabilities
osv·2019-01-09·CVSS 4.7
CVE-2018-0495 [MEDIUM] nss vulnerabilities
nss vulnerabilities
Keegan Ryan discovered that NSS incorrectly handled ECDSA key generation.
A local attacker could possibly use this issue to perform a cache-timing
attack and recover private ECDSA keys. (CVE-2018-0495)
It was discovered that NSS incorrectly handled certain v2-compatible
ClientHello messages. A remote attacker could possibly use this issue to
perform a replay attack. (CVE-2018-12384)
It was discovered that NSS incorrectly handled certain padding oracles. A
remote attacker could possibly use this issue to perform a variant of the
Bleichenbacher attack. (CVE-2018-12404)
Ubuntu
NSS vulnerabilities
vendor_ubuntu·2019-02-18·CVSS 4.7
CVE-2018-0495 [MEDIUM] NSS vulnerabilities
Title: NSS vulnerabilities
Summary: Several security issues were fixed in NSS.
USN-3850-1 fixed several vulnerabilities in NSS. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Keegan Ryan discovered that NSS incorrectly handled ECDSA key generation.
A local attacker could possibly use this issue to perform a cache-timing
attack and recover private ECDSA keys. (CVE-2018-0495)
It was discovered that NSS incorrectly handled certain v2-compatible
ClientHello messages. A remote attacker could possibly use this issue to
perform a replay attack. (CVE-2018-12384)
It was discovered that NSS incorrectly handled certain padding oracles. A
remote attacker could possibly use this issue to perform a variant of the
Bleichenbacher attack. (CVE-2018-1240
Ubuntu
NSS vulnerabilities
vendor_ubuntu·2019-01-09·CVSS 4.7
CVE-2018-0495 [MEDIUM] NSS vulnerabilities
Title: NSS vulnerabilities
Summary: Several security issues were fixed in NSS.
Keegan Ryan discovered that NSS incorrectly handled ECDSA key generation.
A local attacker could possibly use this issue to perform a cache-timing
attack and recover private ECDSA keys. (CVE-2018-0495)
It was discovered that NSS incorrectly handled certain v2-compatible
ClientHello messages. A remote attacker could possibly use this issue to
perform a replay attack. (CVE-2018-12384)
It was discovered that NSS incorrectly handled certain padding oracles. A
remote attacker could possibly use this issue to perform a variant of the
Bleichenbacher attack. (CVE-2018-12404)
Instructions: After a standard system update you need to restart any applications that
use NSS, such as Evolution, to make all the necessary c
Red Hat
nss: ServerHello.random is all zeros when handling a v2-compatible ClientHello
vendor_redhat·2018-09-03·CVSS 5.9
CVE-2018-12384 [MEDIUM] nss: ServerHello.random is all zeros when handling a v2-compatible ClientHello
nss: ServerHello.random is all zeros when handling a v2-compatible ClientHello
When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead. This results in full malleability of the ClientHello for SSLv2 used for TLS 1.2 in all versions prior to NSS 3.39. This does not impact TLS 1.3.
A flaw was found in the way NSS responded to an SSLv2-compatible ClientHello with a ServerHello that had an all-zero random. A man-in-the-middle attacker could use this flaw in a passive replay attack.
Package: nss (Red Hat Enterprise Linux 5) - Not affected
Package: nss (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-12384: nss - When handling a SSLv2-compatible ClientHello request, the server doesn't generat...
vendor_debian·2018·CVSS 5.9
CVE-2018-12384 [MEDIUM] CVE-2018-12384: nss - When handling a SSLv2-compatible ClientHello request, the server doesn't generat...
When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead. This results in full malleability of the ClientHello for SSLv2 used for TLS 1.2 in all versions prior to NSS 3.39. This does not impact TLS 1.3.
Scope: local
bookworm: resolved (fixed in 2:3.39-1)
bullseye: resolved (fixed in 2:3.39-1)
forky: resolved (fixed in 2:3.39-1)
sid: resolved (fixed in 2:3.39-1)
trixie: resolved (fixed in 2:3.39-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-12384 nss: ServerHello.random is all zeros when handling a v2-compatible ClientHello [fedora-all]
bugzilla·2018-09-03·CVSS 5.9
CVE-2018-12384 [MEDIUM] CVE-2018-12384 nss: ServerHello.random is all zeros when handling a v2-compatible ClientHello [fedora-all]
CVE-2018-12384 nss: ServerHello.random is all zeros when handling a v2-compatible ClientHello [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affect
Bugzilla
CVE-2018-12384 nss: ServerHello.random is all zeros when handling a v2-compatible ClientHello
bugzilla·2018-08-24·CVSS 5.9
CVE-2018-12384 [MEDIUM] CVE-2018-12384 nss: ServerHello.random is all zeros when handling a v2-compatible ClientHello
CVE-2018-12384 nss: ServerHello.random is all zeros when handling a v2-compatible ClientHello
A flaw was found with NSS library when compiled with a server application. A man-in-the-middle attacker could use this flaw in a passive replay attack.
The most severe issue for confidentiality is for stream ciphers (and AES-GCM), as the server may encrypt different data with the exact same key stream and idempotency, the server may perform same action multiple times without proper authentication
Discussion:
External References:
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.39_release_notes
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.36.5_release_notes
---
Created nss tracking bugs for this issue:
Affects: fedora-all [bug 1624704]
---
Acknowl
Bugzilla
ServerHello.random is all zero when handling a v2-compatible ClientHello
bugzilla·2018-08-14
[CRITICAL] ServerHello.random is all zero when handling a v2-compatible ClientHello
ServerHello.random is all zero when handling a v2-compatible ClientHello
When we added the very first support for TLS 1.3 in bug 1057463, that moved the generation of the ServerHello.random to ssl3_HandleClientHello():
https://searchfox.org/nss/diff/e89d3055c719e257017518b56dff5cf4b7f6d480/lib/ssl/ssl3con.c#8109
Unfortunately, that removed the call to ssl3_GetNewRandom() on the server side when handling an SSLv2-compatible ClientHello. It was previously in ssl3_SendServerHello(). Now, if an SSLv2-compatible ClientHello is received, the server doesn't generate a new random: it sends an all-zero value.
This results in full malleability of the ClientHello. The only restrictions are minor: an attacker can't negotiate TLS 1.3, an extended master secret, or to include the downgrade SCSV if i
2019-04-29
Published