USN-740-1: NSS vulnerability

17 March 2009

nss, firefox vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 8.10
  • Ubuntu 8.04 LTS
  • Ubuntu 7.10
  • Ubuntu 6.06 LTS

Software Description

  • nss
  • firefox


The MD5 algorithm is known not to be collision resistant. This update blacklists the proof of concept rogue certificate authority as discussed in

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 8.10
libnss3-1d -
Ubuntu 8.04 LTS
libnss3-0d -
libnss3-1d -
Ubuntu 7.10
libnss3-0d - 3.11.5-3ubuntu0.7.10.2
Ubuntu 6.06 LTS
libnss3 - 1.5.dfsg+

To update your system, please follow these instructions:

After a standard system upgrade you need to restart your session to effect the necessary changes.