It was found that NSS accepted weak Diffie-Hellman Key exchange (DHKE) parameters. This could possibly lead to weak encryption being used in communication between the client and the server.
Find out more about CVE-2014-1491 from the MITRE CVE dictionary dictionary and NIST NVD.
Base Score | 4.3 |
---|---|
Base Metrics | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Access Vector | Network |
Access Complexity | Medium |
Authentication | None |
Confidentiality Impact | Partial |
Integrity Impact | None |
Availability Impact | None |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Platform | Errata | Release Date |
---|---|---|
RHEV Hypervisor for RHEL-6 (rhev-hypervisor6) | RHSA-2014:0979 | 2014-07-29 |
Red Hat Enterprise Linux 5 (nss) | RHSA-2014:1246 | 2014-09-16 |
Red Hat Enterprise Linux 6 (nss) | RHSA-2014:0917 | 2014-07-22 |
Platform | Package | State |
---|---|---|
Red Hat Enterprise Linux 7 | nss | Not affected |