Amazon Linux AMI : nss (ALAS-2011-21)

high Nessus Plugin ID 69580

Synopsis

The remote Amazon Linux AMI host is missing a security update.

Description

It was found that the Malaysia-based Digicert Sdn. Bhd. subordinate Certificate Authority (CA) issued HTTPS certificates with weak keys.
This update renders any HTTPS certificates signed by that CA as untrusted. This covers all uses of the certificates, including SSL, S/MIME, and code signing. Note: Digicert Sdn. Bhd. is not the same company as found at digicert.com.

Solution

Run 'yum update nss' to update your system.

See Also

https://alas.aws.amazon.com/ALAS-2011-21.html

Plugin Details

Severity: High

ID: 69580

File Name: ala_ALAS-2011-21.nasl

Version: 1.5

Type: local

Agent: unix

Published: 9/4/2013

Updated: 4/18/2018

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Vulnerability Information

CPE: p-cpe:/a:amazon:linux:nss, p-cpe:/a:amazon:linux:nss-debuginfo, p-cpe:/a:amazon:linux:nss-devel, p-cpe:/a:amazon:linux:nss-pkcs11-devel, p-cpe:/a:amazon:linux:nss-sysinit, p-cpe:/a:amazon:linux:nss-tools, cpe:/o:amazon:linux

Required KB Items: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

Patch Publication Date: 11/19/2011

Reference Information

ALAS: 2011-21

RHSA: 2011:1444