CVE Vulnerabilities

CVE-2015-7575

Published: Jan 09, 2016 | Modified: Apr 12, 2025
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
5.8 MODERATE
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision.

Affected Software

NameVendorStart VersionEnd Version
Network_security_servicesMozilla*3.20.1 (including)
Oracle Java for Red Hat Enterprise Linux 5RedHatjava-1.7.0-oracle-1:1.7.0.95-1jpp.1.el5_11*
Oracle Java for Red Hat Enterprise Linux 6RedHatjava-1.8.0-oracle-1:1.8.0.71-1jpp.1.el6_7*
Oracle Java for Red Hat Enterprise Linux 6RedHatjava-1.7.0-oracle-1:1.7.0.95-1jpp.1.el6_7*
Oracle Java for Red Hat Enterprise Linux 7RedHatjava-1.8.0-oracle-1:1.8.0.71-1jpp.1.el7*
Oracle Java for Red Hat Enterprise Linux 7RedHatjava-1.7.0-oracle-1:1.7.0.95-1jpp.2.el7*
Red Hat Enterprise Linux 5RedHatjava-1.7.0-openjdk-1:1.7.0.95-2.6.4.1.el5_11*
Red Hat Enterprise Linux 5 SupplementaryRedHatjava-1.7.0-ibm-1:1.7.0.9.30-1jpp.1.el5*
Red Hat Enterprise Linux 5 SupplementaryRedHatjava-1.6.0-ibm-1:1.6.0.16.20-1jpp.1.el5*
Red Hat Enterprise Linux 6RedHatnss-0:3.19.1-8.el6_7*
Red Hat Enterprise Linux 6RedHatopenssl-0:1.0.1e-42.el6_7.2*
Red Hat Enterprise Linux 6RedHatgnutls-0:2.8.5-19.el6_7*
Red Hat Enterprise Linux 6RedHatjava-1.8.0-openjdk-1:1.8.0.71-1.b15.el6_7*
Red Hat Enterprise Linux 6RedHatjava-1.7.0-openjdk-1:1.7.0.95-2.6.4.0.el6_7*
Red Hat Enterprise Linux 6 SupplementaryRedHatjava-1.7.1-ibm-1:1.7.1.3.30-1jpp.2.el6_7*
Red Hat Enterprise Linux 6 SupplementaryRedHatjava-1.6.0-ibm-1:1.6.0.16.20-1jpp.1.el6_7*
Red Hat Enterprise Linux 7RedHatnss-0:3.19.1-19.el7_2*
Red Hat Enterprise Linux 7RedHatopenssl-1:1.0.1e-51.el7_2.2*
Red Hat Enterprise Linux 7RedHatgnutls-0:3.3.8-14.el7_2*
Red Hat Enterprise Linux 7RedHatjava-1.8.0-openjdk-1:1.8.0.71-2.b15.el7_2*
Red Hat Enterprise Linux 7RedHatjava-1.7.0-openjdk-1:1.7.0.95-2.6.4.0.el7_2*
Red Hat Enterprise Linux 7 SupplementaryRedHatjava-1.8.0-ibm-1:1.8.0.2.10-1jpp.1.el7*
Red Hat Enterprise Linux 7 SupplementaryRedHatjava-1.7.1-ibm-1:1.7.1.3.30-1jpp.1.el7*
Red Hat Satellite 5.6RedHatjava-1.7.0-ibm-1:1.7.0.9.40-1jpp.1.el5*
Red Hat Satellite 5.6RedHatjava-1.7.1-ibm-1:1.7.1.3.40-1jpp.1.el6_7*
Red Hat Satellite 5.6RedHatspacewalk-java-0:2.0.2-109.el5sat*
Red Hat Satellite 5.7RedHatjava-1.7.1-ibm-1:1.7.1.3.40-1jpp.1.el6_7*
Red Hat Satellite 5.7RedHatspacewalk-java-0:2.3.8-146.el6sat*
FirefoxUbuntuartful*
FirefoxUbuntubionic*
FirefoxUbuntucosmic*
FirefoxUbuntudevel*
FirefoxUbuntudisco*
FirefoxUbuntuprecise*
FirefoxUbuntutrusty*
FirefoxUbuntuupstream*
FirefoxUbuntuvivid*
FirefoxUbuntuwily*
FirefoxUbuntuxenial*
FirefoxUbuntuyakkety*
FirefoxUbuntuzesty*
Gnutls26Ubuntuesm-infra-legacy/trusty*
Gnutls26Ubuntuprecise*
Gnutls26Ubuntutrusty*
Gnutls26Ubuntutrusty/esm*
Gnutls28Ubuntuprecise*
Gnutls28Ubuntutrusty*
Gnutls28Ubuntuupstream*
Gnutls28Ubuntuvivid*
Gnutls28Ubuntuvivid/stable-phone-overlay*
Gnutls28Ubuntuvivid/ubuntu-core*
MbedtlsUbuntuupstream*
NssUbuntuesm-infra-legacy/trusty*
NssUbuntuprecise*
NssUbuntutrusty*
NssUbuntutrusty/esm*
NssUbuntuupstream*
NssUbuntuvivid*
NssUbuntuvivid/stable-phone-overlay*
NssUbuntuwily*
Openjdk-6Ubuntuprecise*
Openjdk-6Ubuntutrusty*
Openjdk-6Ubuntuvivid*
Openjdk-6Ubuntuwily*
Openjdk-7Ubuntuprecise*
Openjdk-7Ubuntutrusty*
Openjdk-7Ubuntuvivid*
Openjdk-7Ubuntuwily*
Openjdk-8Ubuntuupstream*
Openjdk-8Ubuntuvivid*
Openjdk-8Ubuntuwily*
OpensslUbuntuprecise*
OpensslUbuntuupstream*
PolarsslUbuntuprecise*
PolarsslUbuntutrusty*
PolarsslUbuntuupstream*
PolarsslUbuntuvivid*
PolarsslUbuntuwily*
ThunderbirdUbuntuartful*
ThunderbirdUbuntubionic*
ThunderbirdUbuntucosmic*
ThunderbirdUbuntudevel*
ThunderbirdUbuntudisco*
ThunderbirdUbuntuprecise*
ThunderbirdUbuntutrusty*
ThunderbirdUbuntuupstream*
ThunderbirdUbuntuvivid*
ThunderbirdUbuntuwily*
ThunderbirdUbuntuxenial*
ThunderbirdUbuntuyakkety*
ThunderbirdUbuntuzesty*

References