Users are advised to upgrade their systems as soon as possible

Dec 30, 2013 09:11 GMT  ·  By

In a security notice, Canonical published details about an NSS vulnerability in its Ubuntu 13.10, Ubuntu 13.04, Ubuntu 12.10, Ubuntu 12.04 LTS, and Ubuntu 10.04 LTS operating systems.

According to the company, fraudulent security certificates could allow sensitive information to be exposed when accessing the Internet.

It has been discovered that an intermediate certificate was incorrectly issued by a subordinate certificate authority of a trusted CA included in NSS. This intermediate certificate could have been used in a man-in-the-middle attack, and it has such been marked as untrusted in this update.

For a more detailed description of the problems, you can see Canonical's security notification.

The security flaws can be fixed if you upgrade your system(s) to the latest libnss3 package specific to each distribution. To apply the update, run the Update Manager application.

In general, a standard system update will make all the necessary changes, but this time a system restart will be necessary to implement them.