ALAS-2012-102


Amazon Linux AMI Security Advisory: ALAS-2012-102
Advisory Release Date: 2014-09-14 16:42 Pacific
Severity: Medium
References: RHSA-2012-0973 

Issue Overview:

It was found that a Certificate Authority (CA) issued a subordinate CA certificate to its customer, that could be used to issue certificates for any name. This update renders the subordinate CA certificate as untrusted.


Affected Packages:

nss


Issue Correction:
Run yum update nss to update your system.

New Packages:
i686:
    nss-debuginfo-3.13.3-8.25.amzn1.i686
    nss-tools-3.13.3-8.25.amzn1.i686
    nss-pkcs11-devel-3.13.3-8.25.amzn1.i686
    nss-devel-3.13.3-8.25.amzn1.i686
    nss-sysinit-3.13.3-8.25.amzn1.i686
    nss-3.13.3-8.25.amzn1.i686

src:
    nss-3.13.3-8.25.amzn1.src

x86_64:
    nss-pkcs11-devel-3.13.3-8.25.amzn1.x86_64
    nss-tools-3.13.3-8.25.amzn1.x86_64
    nss-3.13.3-8.25.amzn1.x86_64
    nss-sysinit-3.13.3-8.25.amzn1.x86_64
    nss-debuginfo-3.13.3-8.25.amzn1.x86_64
    nss-devel-3.13.3-8.25.amzn1.x86_64