{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/alpinelinux3.18els/vex/2018/cve-2018-12384-els_os-alpinelinux3_18els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-03T19:36:47Z",
      "generator": {
        "date": "2026-07-03T19:36:47Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2018-12384-ELS_OS-ALPINELINUX3.18ELS",
      "initial_release_date": "2018-01-01T00:00:00Z",
      "revision_history": [
        {
          "date": "2018-01-01T00:00:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-05-27T14:31:38Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-07-03T19:36:47Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2018-12384"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "nss-3.94-r0.aarch64",
                "product": {
                  "name": "nss-3.94-r0.aarch64",
                  "product_id": "nss-3.94-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/alpine/nss@3.94-r0?arch=aarch64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "nss-tools-3.94-r0.aarch64",
                "product": {
                  "name": "nss-tools-3.94-r0.aarch64",
                  "product_id": "nss-tools-3.94-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/alpine/nss-tools@3.94-r0?arch=aarch64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "nss-dev-3.94-r0.aarch64",
                "product": {
                  "name": "nss-dev-3.94-r0.aarch64",
                  "product_id": "nss-dev-3.94-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/alpine/nss-dev@3.94-r0?arch=aarch64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "aarch64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "nss-3.94-r0.x86_64",
                "product": {
                  "name": "nss-3.94-r0.x86_64",
                  "product_id": "nss-3.94-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/alpine/nss@3.94-r0?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "nss-tools-3.94-r0.x86_64",
                "product": {
                  "name": "nss-tools-3.94-r0.x86_64",
                  "product_id": "nss-tools-3.94-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/alpine/nss-tools@3.94-r0?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "nss-dev-3.94-r0.x86_64",
                "product": {
                  "name": "nss-dev-3.94-r0.x86_64",
                  "product_id": "nss-dev-3.94-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/alpine/nss-dev@3.94-r0?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Alpine Linux 3.18",
                "product": {
                  "name": "Alpine Linux 3.18",
                  "product_id": "Alpine-Linux-3.18",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:alpinelinux:alpine_linux:3.18:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Alpine Linux"
          }
        ],
        "category": "vendor",
        "name": "Alpine Linux"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "nss-3.94.tuxcare.els1-r0.aarch64",
                "product": {
                  "name": "nss-3.94.tuxcare.els1-r0.aarch64",
                  "product_id": "nss-3.94.tuxcare.els1-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/nss@3.94.tuxcare.els1-r0?arch=aarch64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "nss-tools-3.94.tuxcare.els1-r0.aarch64",
                "product": {
                  "name": "nss-tools-3.94.tuxcare.els1-r0.aarch64",
                  "product_id": "nss-tools-3.94.tuxcare.els1-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/nss-tools@3.94.tuxcare.els1-r0?arch=aarch64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "nss-dev-3.94.tuxcare.els1-r0.aarch64",
                "product": {
                  "name": "nss-dev-3.94.tuxcare.els1-r0.aarch64",
                  "product_id": "nss-dev-3.94.tuxcare.els1-r0.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/nss-dev@3.94.tuxcare.els1-r0?arch=aarch64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "aarch64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "nss-3.94.tuxcare.els1-r0.x86_64",
                "product": {
                  "name": "nss-3.94.tuxcare.els1-r0.x86_64",
                  "product_id": "nss-3.94.tuxcare.els1-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/nss@3.94.tuxcare.els1-r0?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "nss-tools-3.94.tuxcare.els1-r0.x86_64",
                "product": {
                  "name": "nss-tools-3.94.tuxcare.els1-r0.x86_64",
                  "product_id": "nss-tools-3.94.tuxcare.els1-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/nss-tools@3.94.tuxcare.els1-r0?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "nss-dev-3.94.tuxcare.els1-r0.x86_64",
                "product": {
                  "name": "nss-dev-3.94.tuxcare.els1-r0.x86_64",
                  "product_id": "nss-dev-3.94.tuxcare.els1-r0.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/nss-dev@3.94.tuxcare.els1-r0?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "nss-3.94.tuxcare.els1-r0.aarch64 as a component of Alpine Linux 3.18",
          "product_id": "Alpine-Linux-3.18:nss-3.94.tuxcare.els1-r0.aarch64"
        },
        "product_reference": "nss-3.94.tuxcare.els1-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "nss-3.94-r0.aarch64 as a component of Alpine Linux 3.18",
          "product_id": "Alpine-Linux-3.18:nss-3.94-r0.aarch64"
        },
        "product_reference": "nss-3.94-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "nss-3.94.tuxcare.els1-r0.x86_64 as a component of Alpine Linux 3.18",
          "product_id": "Alpine-Linux-3.18:nss-3.94.tuxcare.els1-r0.x86_64"
        },
        "product_reference": "nss-3.94.tuxcare.els1-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "nss-3.94-r0.x86_64 as a component of Alpine Linux 3.18",
          "product_id": "Alpine-Linux-3.18:nss-3.94-r0.x86_64"
        },
        "product_reference": "nss-3.94-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "nss-tools-3.94.tuxcare.els1-r0.aarch64 as a component of Alpine Linux 3.18",
          "product_id": "Alpine-Linux-3.18:nss-tools-3.94.tuxcare.els1-r0.aarch64"
        },
        "product_reference": "nss-tools-3.94.tuxcare.els1-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "nss-tools-3.94-r0.aarch64 as a component of Alpine Linux 3.18",
          "product_id": "Alpine-Linux-3.18:nss-tools-3.94-r0.aarch64"
        },
        "product_reference": "nss-tools-3.94-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "nss-tools-3.94.tuxcare.els1-r0.x86_64 as a component of Alpine Linux 3.18",
          "product_id": "Alpine-Linux-3.18:nss-tools-3.94.tuxcare.els1-r0.x86_64"
        },
        "product_reference": "nss-tools-3.94.tuxcare.els1-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "nss-tools-3.94-r0.x86_64 as a component of Alpine Linux 3.18",
          "product_id": "Alpine-Linux-3.18:nss-tools-3.94-r0.x86_64"
        },
        "product_reference": "nss-tools-3.94-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "nss-dev-3.94.tuxcare.els1-r0.aarch64 as a component of Alpine Linux 3.18",
          "product_id": "Alpine-Linux-3.18:nss-dev-3.94.tuxcare.els1-r0.aarch64"
        },
        "product_reference": "nss-dev-3.94.tuxcare.els1-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "nss-dev-3.94-r0.aarch64 as a component of Alpine Linux 3.18",
          "product_id": "Alpine-Linux-3.18:nss-dev-3.94-r0.aarch64"
        },
        "product_reference": "nss-dev-3.94-r0.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "nss-dev-3.94.tuxcare.els1-r0.x86_64 as a component of Alpine Linux 3.18",
          "product_id": "Alpine-Linux-3.18:nss-dev-3.94.tuxcare.els1-r0.x86_64"
        },
        "product_reference": "nss-dev-3.94.tuxcare.els1-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "nss-dev-3.94-r0.x86_64 as a component of Alpine Linux 3.18",
          "product_id": "Alpine-Linux-3.18:nss-dev-3.94-r0.x86_64"
        },
        "product_reference": "nss-dev-3.94-r0.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.18"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2018-12384",
      "cwe": {
        "id": "CWE-335",
        "name": "Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)"
      },
      "notes": [
        {
          "category": "description",
          "text": "When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead. This results in full malleability of the ClientHello for SSLv2 used for TLS 1.2 in all versions prior to NSS 3.39. This does not impact TLS 1.3.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Alpine-Linux-3.18:nss-3.94-r0.aarch64",
          "Alpine-Linux-3.18:nss-3.94-r0.x86_64",
          "Alpine-Linux-3.18:nss-3.94.tuxcare.els1-r0.aarch64",
          "Alpine-Linux-3.18:nss-3.94.tuxcare.els1-r0.x86_64",
          "Alpine-Linux-3.18:nss-dev-3.94-r0.aarch64",
          "Alpine-Linux-3.18:nss-dev-3.94-r0.x86_64",
          "Alpine-Linux-3.18:nss-dev-3.94.tuxcare.els1-r0.aarch64",
          "Alpine-Linux-3.18:nss-dev-3.94.tuxcare.els1-r0.x86_64",
          "Alpine-Linux-3.18:nss-tools-3.94-r0.aarch64",
          "Alpine-Linux-3.18:nss-tools-3.94-r0.x86_64",
          "Alpine-Linux-3.18:nss-tools-3.94.tuxcare.els1-r0.aarch64",
          "Alpine-Linux-3.18:nss-tools-3.94.tuxcare.els1-r0.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2018-12384"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.mozilla.org/show_bug.cgi?id=CVE-2018-12384",
          "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=CVE-2018-12384"
        },
        {
          "category": "external",
          "summary": "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html",
          "url": "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"
        }
      ],
      "release_date": "2019-04-29T15:29:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-05-26T16:10:27.226347Z",
          "details": "This issue is only reachable when an NSS-based server prior to 3.39 processes the legacy SSLv2‑compatible ClientHello for a TLS 1.2 handshake; TLS 1.3 is unaffected. Exploitation requires an active network attacker and a client using that obsolete hello format, and available analysis indicates it does not expose the premaster secret or bypass Finished verification, making the practical impact primarily downgrade/handshake manipulation rather than direct key compromise. In centrally managed enterprise VM/server environments that negotiate standard (non‑SSLv2‑compatible) ClientHello messages, the vulnerable code path is unlikely to be exercised, so this can be safely deprioritized unless you explicitly support SSLv2‑compatible ClientHello on an NSS server older than 3.39.",
          "product_ids": [
            "Alpine-Linux-3.18:nss-3.94-r0.aarch64",
            "Alpine-Linux-3.18:nss-3.94-r0.x86_64",
            "Alpine-Linux-3.18:nss-3.94.tuxcare.els1-r0.aarch64",
            "Alpine-Linux-3.18:nss-3.94.tuxcare.els1-r0.x86_64",
            "Alpine-Linux-3.18:nss-dev-3.94-r0.aarch64",
            "Alpine-Linux-3.18:nss-dev-3.94-r0.x86_64",
            "Alpine-Linux-3.18:nss-dev-3.94.tuxcare.els1-r0.aarch64",
            "Alpine-Linux-3.18:nss-dev-3.94.tuxcare.els1-r0.x86_64",
            "Alpine-Linux-3.18:nss-tools-3.94-r0.aarch64",
            "Alpine-Linux-3.18:nss-tools-3.94-r0.x86_64",
            "Alpine-Linux-3.18:nss-tools-3.94.tuxcare.els1-r0.aarch64",
            "Alpine-Linux-3.18:nss-tools-3.94.tuxcare.els1-r0.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v2": {
            "accessComplexity": "MEDIUM",
            "accessVector": "NETWORK",
            "authentication": "NONE",
            "availabilityImpact": "NONE",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "PARTIAL",
            "integrityImpact": "NONE",
            "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
            "version": "2.0"
          },
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.0"
          },
          "products": [
            "Alpine-Linux-3.18:nss-3.94-r0.aarch64",
            "Alpine-Linux-3.18:nss-3.94-r0.x86_64",
            "Alpine-Linux-3.18:nss-3.94.tuxcare.els1-r0.aarch64",
            "Alpine-Linux-3.18:nss-3.94.tuxcare.els1-r0.x86_64",
            "Alpine-Linux-3.18:nss-dev-3.94-r0.aarch64",
            "Alpine-Linux-3.18:nss-dev-3.94-r0.x86_64",
            "Alpine-Linux-3.18:nss-dev-3.94.tuxcare.els1-r0.aarch64",
            "Alpine-Linux-3.18:nss-dev-3.94.tuxcare.els1-r0.x86_64",
            "Alpine-Linux-3.18:nss-tools-3.94-r0.aarch64",
            "Alpine-Linux-3.18:nss-tools-3.94-r0.x86_64",
            "Alpine-Linux-3.18:nss-tools-3.94.tuxcare.els1-r0.aarch64",
            "Alpine-Linux-3.18:nss-tools-3.94.tuxcare.els1-r0.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}