Amazon Linux AMI : nss (ALAS-2012-102)

high Nessus Plugin ID 69592

Synopsis

The remote Amazon Linux AMI host is missing a security update.

Description

It was found that a Certificate Authority (CA) issued a subordinate CA certificate to its customer, that could be used to issue certificates for any name. This update renders the subordinate CA certificate as untrusted.

Solution

Run 'yum update nss' to update your system.

See Also

https://alas.aws.amazon.com/ALAS-2012-102.html

Plugin Details

Severity: High

ID: 69592

File Name: ala_ALAS-2012-102.nasl

Version: 1.5

Type: local

Agent: unix

Published: 9/4/2013

Updated: 4/18/2018

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Vulnerability Information

CPE: p-cpe:/a:amazon:linux:nss, p-cpe:/a:amazon:linux:nss-debuginfo, p-cpe:/a:amazon:linux:nss-devel, p-cpe:/a:amazon:linux:nss-pkcs11-devel, p-cpe:/a:amazon:linux:nss-sysinit, p-cpe:/a:amazon:linux:nss-tools, cpe:/o:amazon:linux

Required KB Items: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

Patch Publication Date: 7/5/2012

Reference Information

ALAS: 2012-102

RHSA: 2012:0973