Summary
The remote host is missing an update to nss
announced via advisory DSA 2339-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%202339-1
Insight
This update to the NSS cryptographic libraries revokes the trust in the DigiCert Sdn. Bhd certificate authority. More information can be found in the Mozilla Security Blog:
http://blog.mozilla.com/security/2011/11/03/revoking-trust-in-digicert-sdn-bhd-intermediate-certificate-authority/
This update also fixes an insecure load path for pkcs11.txt configuration file (CVE-2011-3640).
For the oldstable distribution (lenny), this problem has been fixed in version 3.12.3.1-0lenny7.
For the stable distribution (squeeze), this problem has been fixed in version 3.12.8-1+squeeze4.
For the unstable distribution (sid), this problem has been fixed in version 3.13.1.with.ckbi.1.88-1.
We recommend that you upgrade your nss packages.
Severity
Classification
-
CVE CVE-2011-3640 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities