{"id":"MGASA-2014-0024","summary":"Updated nss packages fix security vulnerability","details":"Updated nss packages fix security vulnerability:\n\nThe ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla\nNetwork Security Services (NSS) before 3.15.4, when the TLS False\nStart feature is enabled, allows man-in-the-middle attackers to spoof\nSSL servers by using an arbitrary X.509 certificate during certain\nhandshake traffic (CVE-2013-1740).\n","modified":"2026-02-04T03:23:43.890837Z","published":"2014-01-21T16:23:58Z","related":["CVE-2013-1740"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0024.html"},{"type":"REPORT","url":"https://developer.mozilla.org/en-US/docs/NSS/NSS_3.15.4_release_notes"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=12342"}],"affected":[{"package":{"name":"nss","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/nss?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.15.4-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0024.json"}}],"schema_version":"1.7.3","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}