OracleVM 3.3 / 3.4 : nssnss-util (OVMSA-2016-0159)

Medium Nessus Plugin ID 94930


The remote OracleVM host is missing one or more security updates.


The remote OracleVM system is missing necessary patches to address critical security updates :


- Added nss-vendor.patch to change vendor

- Mozilla #1314604 / Red Hat (CVE-2016-8635)

- remove disable_hw_gcm.patch which hasn't been used since 3.16.1

- Rebase to NSS 3.21.3

- Resolves: #1383885


- Rebase to nss-3.21.3

- Remove patch for CVE-2016-1950, which is included in the release

- Related: Bug 1347908

- Added upstream patch for (CVE-2016-1950)

- Rebase to nss-util from nss 3.21

- Resolves: Bug 1297890 - Rebase RHEL 6.8 to NSS-util 3.21 in preparation for Firefox 45


Update the affected packages.

See Also

Plugin Details

Severity: Medium

ID: 94930

File Name: oraclevm_OVMSA-2016-0159.nasl

Version: 2.7

Type: local

Published: 2016/11/17

Updated: 2019/09/27

Dependencies: 12634

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

CVSS v3.0

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:oracle:vm:nss, p-cpe:/a:oracle:vm:nss-sysinit, p-cpe:/a:oracle:vm:nss-tools, p-cpe:/a:oracle:vm:nss-util, cpe:/o:oracle:vm_server:3.3, cpe:/o:oracle:vm_server:3.4

Required KB Items: Host/local_checks_enabled, Host/OracleVM/release, Host/OracleVM/rpm-list

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2016/11/16

Vulnerability Publication Date: 2016/03/13

Reference Information

CVE: CVE-2016-1950, CVE-2016-8635