OracleVM 3.3 / 3.4 : nss (OVMSA-2017-0109)

High Nessus Plugin ID 100529


The remote OracleVM host is missing one or more security updates.


The remote OracleVM system is missing necessary patches to address critical security updates :

- Added nss-vendor.patch to change vendor

- Temporarily disable some tests until expired PayPalEE.cert is renewed

- Fix zero-length record treatment for stream ciphers and SSLv2

- Include CKBI 2.14 and updated CA constraints from NSS 3.28.5


Update the affected nss / nss-sysinit / nss-tools packages.

See Also

Plugin Details

Severity: High

ID: 100529

File Name: oraclevm_OVMSA-2017-0109.nasl

Version: $Revision: 3.1 $

Type: local

Published: 2017/05/31

Modified: 2017/05/31

Dependencies: 12634

Risk Information

Risk Factor: High

Vulnerability Information

CPE: p-cpe:/a:oracle:vm:nss, p-cpe:/a:oracle:vm:nss-sysinit, p-cpe:/a:oracle:vm:nss-tools, cpe:/o:oracle:vm_server:3.3, cpe:/o:oracle:vm_server:3.4

Required KB Items: Host/local_checks_enabled, Host/OracleVM/release, Host/OracleVM/rpm-list

Patch Publication Date: 2017/05/30