---
title: "CVE-2015-2721\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2015-2721?format=md
keywords: index, follow
---

# CVE-2015-2721

Publication date 5 July 2015

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla
Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1,
Thunderbird before 38.1, and other products, does not properly determine
state transitions for the TLS state machine, which allows man-in-the-middle
attackers to defeat cryptographic protection mechanisms by blocking
messages, as demonstrated by removing a forward-secrecy property by
blocking a ServerKeyExchange message, aka a "SMACK SKIP-TLS" issue.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| firefox | 15.04 vivid | Fixed 39.0+build5-0ubuntu0.15.04.1 |
| 14.10 utopic | Fixed 39.0+build5-0ubuntu0.14.10.1 |
| 14.04 LTS trusty | Fixed 39.0+build5-0ubuntu0.14.04.1 |
| 12.04 LTS precise | Fixed 39.0+build5-0ubuntu0.12.04.2 |
| nss | 15.04 vivid | Fixed 2:3.19.2-0ubuntu15.04.1 |
| 14.10 utopic | Fixed 2:3.19.2-0ubuntu0.14.10.1 |
| 14.04 LTS trusty | Fixed 2:3.19.2-0ubuntu0.14.04.1 |
| 12.04 LTS precise | Fixed 3.19.2-0ubuntu0.12.04.1 |
| thunderbird | 15.04 vivid | Fixed 1:31.8.0+build1-0ubuntu0.15.04.1 |
| 14.10 utopic | Fixed 1:31.8.0+build1-0ubuntu0.14.10.1 |
| 14.04 LTS trusty | Fixed 1:31.8.0+build1-0ubuntu0.14.04.1 |
| 12.04 LTS precise | Fixed 1:31.8.0+build1-0ubuntu0.12.04.1 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2721)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2015-2721)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2015-2721)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2015-2721)

### Related Ubuntu Security Notices (USN)

+ [USN-2673-1](https://usn.ubuntu.com/USN-2673-1)
+ Thunderbird vulnerabilities
+ 20 July 2015

+ [USN-2672-1](https://usn.ubuntu.com/USN-2672-1)
+ NSS vulnerabilities
+ 9 July 2015

+ [USN-2656-1](https://usn.ubuntu.com/USN-2656-1)
+ Firefox vulnerabilities
+ 9 July 2015

+ [USN-2656-2](https://usn.ubuntu.com/USN-2656-2)
+ Firefox vulnerabilities
+ 15 July 2015

### Other references

* <https://www.mozilla.org/en-US/security/advisories/mfsa2015-71/>
* <https://smacktls.com>
* <https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.19_release_notes>
* <https://bugzilla.mozilla.org/show_bug.cgi?id=1086145>
* <http://www.mozilla.org/security/announce/2015/mfsa2015-71.html>
* <https://www.cve.org/CVERecord?id=CVE-2015-2721>
