CVE-2019-11727: Medium severity ibm cognos analytics vulnerability
A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those are the only ones advertised by server in CertificateRequest in TLS 1.3. PKCS#1 v1.5 signatures should not be used for TLS 1.3 messages.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-21/#CVE-2019-11727
Other sources
A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those are the only ones advertised by server in CertificateRequest in TLS 1.3. PKCS#1 v1.5 signatures should not be used for TLS 1.3 messages.
— Mozilla
Mozilla Firefox could allow a remote attacker to bypass security restrictions. By persuading a victim to visit a specially-crafted Web site, an attacker could exploit this vulnerability to force Network Security Services (NSS) to sign PKCS#1 v1.5 signatures to be used for TLS 1.3 messages.
— IBM
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-11727?
CVE-2019-11727 is a vulnerability in Network Security Services (NSS) that allows for the signing of CertificateVerify with PKCS#1 v1.5 signatures in TLS 1.3 messages.
How severe is CVE-2019-11727?
CVE-2019-11727 has a severity rating of 5.3 (medium).
Which software is affected by CVE-2019-11727?
The software affected by CVE-2019-11727 includes Mozilla Thunderbird, Firefox, and Red Hat NSS.
How can I fix CVE-2019-11727?
To fix CVE-2019-11727, update your software to the recommended versions: Red Hat NSS 3.44.1, Mozilla Thunderbird 68, Mozilla Firefox 68.
Where can I find more information about CVE-2019-11727?
You can find more information about CVE-2019-11727 on the Mozilla and Red Hat security advisories.