ALAS-2013-149


Amazon Linux AMI Security Advisory: ALAS-2013-149
Advisory Release Date: 2014-09-14 17:22 Pacific
Severity: Important
References: RHSA-2013-0213 

Issue Overview:

It was found that a Certificate Authority (CA) mis-issued two intermediate certificates to customers. These certificates could be used to launch man-in-the-middle attacks. This update renders those certificates as untrusted. This covers all uses of the certificates, including SSL, S/MIME, and code signing.


Affected Packages:

nss


Issue Correction:
Run yum update nss to update your system.

New Packages:
i686:
    nss-devel-3.13.6-2.27.amzn1.i686
    nss-debuginfo-3.13.6-2.27.amzn1.i686
    nss-tools-3.13.6-2.27.amzn1.i686
    nss-pkcs11-devel-3.13.6-2.27.amzn1.i686
    nss-sysinit-3.13.6-2.27.amzn1.i686
    nss-3.13.6-2.27.amzn1.i686

src:
    nss-3.13.6-2.27.amzn1.src

x86_64:
    nss-3.13.6-2.27.amzn1.x86_64
    nss-devel-3.13.6-2.27.amzn1.x86_64
    nss-pkcs11-devel-3.13.6-2.27.amzn1.x86_64
    nss-tools-3.13.6-2.27.amzn1.x86_64
    nss-debuginfo-3.13.6-2.27.amzn1.x86_64
    nss-sysinit-3.13.6-2.27.amzn1.x86_64