CVE-2020-25648
20.10.2020, 22:15
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.Enginsight
Vendor | Product | Version |
---|---|---|
mozilla | network_security_services | 𝑥 < 3.58 |
redhat | enterprise_linux | 7.0 |
redhat | enterprise_linux | 8.0 |
oracle | communications_offline_mediation_controller | 12.0.0.3.0 |
oracle | communications_pricing_design_center | 12.0.0.3.0 |
oracle | jd_edwards_enterpriseone_tools | 𝑥 < 9.2.6.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References