Ubuntu Security Notice 1763-2 - USN-1763-1 fixed a vulnerability in NSS. This update provides the NSPR needed to use the new NSS. Nadhem Alfardan and Kenny Paterson discovered that the TLS protocol as used in NSS was vulnerable to a timing side-channel attack known as the "Lucky Thirteen" issue. A remote attacker could use this issue to perform plaintext-recovery attacks via analysis of timing data. Various other issues were also addressed.
14c2109289cf639924ee155649aaf99f56995b1e908629a630645e7226d2101b
============================================================================
Ubuntu Security Notice USN-1763-2
March 14, 2013
nspr update
============================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.10
- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 10.04 LTS
Summary:
NSPR update to work with the new NSS.
Software Description:
- nspr: NetScape Portable Runtime Library
Details:
USN-1763-1 fixed a vulnerability in NSS. This update provides the NSPR
needed to use the new NSS.
Original advisory details:
Nadhem Alfardan and Kenny Paterson discovered that the TLS protocol as used
in NSS was vulnerable to a timing side-channel attack known as the
"Lucky Thirteen" issue. A remote attacker could use this issue to perform
plaintext-recovery attacks via analysis of timing data.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.10:
libnspr4 4.9.5-0ubuntu0.12.10.1
Ubuntu 12.04 LTS:
libnspr4 4.9.5-0ubuntu0.12.04.1
Ubuntu 11.10:
libnspr4 4.9.5-0ubuntu0.11.10.1
Ubuntu 10.04 LTS:
libnspr4-0d 4.9.5-0ubuntu0.10.04.1
After a standard system update you need to restart any applications that
use NSPR, such as Evolution and Chromium, to make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-1763-2
http://www.ubuntu.com/usn/usn-1763-1
https://launchpad.net/bugs/1155295
Package Information:
https://launchpad.net/ubuntu/+source/nspr/4.9.5-0ubuntu0.12.10.1
https://launchpad.net/ubuntu/+source/nspr/4.9.5-0ubuntu0.12.04.1
https://launchpad.net/ubuntu/+source/nspr/4.9.5-0ubuntu0.11.10.1
https://launchpad.net/ubuntu/+source/nspr/4.9.5-0ubuntu0.10.04.1