CVE-2019-17023
Published: 8 January 2020
After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects Firefox < 72.
Priority
CVSS 3 base score: 6.5
Status
Package | Release | Status |
---|---|---|
firefox Launchpad, Ubuntu, Debian |
bionic |
Released
(72.0.1+build1-0ubuntu0.18.04.1)
|
disco |
Released
(72.0.1+build1-0ubuntu0.19.04.1)
|
|
eoan |
Released
(72.0.1+build1-0ubuntu0.19.10.1)
|
|
focal |
Released
(72.0.1+build1-0ubuntu1)
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Released
(72.0)
|
|
xenial |
Released
(72.0.1+build1-0ubuntu0.16.04.1)
|
|
nss Launchpad, Ubuntu, Debian |
bionic |
Released
(2:3.35-2ubuntu2.8)
|
disco |
Ignored
(reached end-of-life)
|
|
eoan |
Released
(2:3.45-1ubuntu2.3)
|
|
focal |
Not vulnerable
(2:3.49.1-1ubuntu1)
|
|
precise |
Not vulnerable
|
|
trusty |
Not vulnerable
|
|
upstream |
Released
(2:3.49-1)
|
|
xenial |
Not vulnerable
(code not compiled)
|
Notes
Author | Note |
---|---|
mdeslaur | nss in xenial is built with NSS_DISABLE_TLS_1_3, so this issue doesn't affect it. |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17023
- https://www.mozilla.org/en-US/security/advisories/mfsa2020-01/#CVE-2019-17023
- https://www.mozilla.org/security/advisories/mfsa2020-01/
- https://ubuntu.com/security/notices/USN-4234-1
- https://ubuntu.com/security/notices/USN-4397-1
- NVD
- Launchpad
- Debian