SB2020010834 - Algorithm Downgrade in firefox (Alpine package)
Published: January 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Algorithm Downgrade (CVE-ID: CVE-2019-17023)
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to insecure negotiation After a HelloRetryRequest in Mozilla NSS that can lead to selection of a less secure protocol (e.g. TLS 1.2 or below) after the HelloRetryRequest TLS 1.3 is sent.
Remediation
Install update from vendor's website.