OracleVM 3.3 / 3.4 : nss (OVMSA-2018-0264)

Medium Nessus Plugin ID 118051


The remote OracleVM host is missing one or more security updates.


The remote OracleVM system is missing necessary patches to address critical security updates :

- Added nss-vendor.patch to change vendor

- Temporarily disable some tests until expired PayPalEE.cert is renewed

- Backport upstream fix for (CVE-2018-12384)

- Remove nss-lockcert-api-change.patch, which turned out to be a mistake (the symbol was not exported from libnss)

- Restore CERT_LockCertTrust and CERT_UnlockCertTrust back in cert.h

- rebuild

- Keep legacy code signing trust flags for backwards compatibility

- Decrease the iteration count of PKCS#12 for compatibility with Windows

- Fix deadlock when a token is re-inserted while a client process is running

- Ignore tests which only works with newer nss-softokn

- Use the correct tarball of NSS 3.36 release

- Ignore EncryptDeriveTest which only works with newer nss-softokn

- Don't skip non-FIPS and ECC test cases in

- Rebase to NSS 3.36.0

- Rebase to NSS 3.36.0 BETA

- Remove upstreamed nss-is-token-present-race.patch

- Revert the upstream changes that default to sql database

- Replace race.patch and nss-3.16-token-init-race.patch with a proper upstream fix

- Don't restrict nss_cycles to sharedb

- Rebase to NSS 3.34.0


Update the affected nss / nss-sysinit / nss-tools packages.

See Also

Plugin Details

Severity: Medium

ID: 118051

File Name: oraclevm_OVMSA-2018-0264.nasl

Version: 1.3

Type: local

Published: 2018/10/11

Updated: 2019/09/27

Dependencies: 12634

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS v3.0

Base Score: 5.9

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Vulnerability Information

CPE: p-cpe:/a:oracle:vm:nss, p-cpe:/a:oracle:vm:nss-sysinit, p-cpe:/a:oracle:vm:nss-tools, cpe:/o:oracle:vm_server:3.3, cpe:/o:oracle:vm_server:3.4

Required KB Items: Host/local_checks_enabled, Host/OracleVM/release, Host/OracleVM/rpm-list

Patch Publication Date: 2018/10/10

Vulnerability Publication Date: 2019/04/29

Reference Information

CVE: CVE-2018-12384