Hide Forgot
It was reported that mod_nss is vulnerable to the issue similar to CVE-2015-3276, where incorrect parsing of multi-keyword cipherstring can lead to an unexpected ciphers list advertising. Acknowledgements: Red Hat would like to thank Martin Poole of Software Maintenance Engineering group for reporting this issue.
The vulnerable code was added to mod_nss via the following commit: https://git.fedorahosted.org/cgit/mod_nss.git/commit/?id=2d1650900f4d47dc43400d826c0f7e1a7c5229b8 And it was released as mod_nss-1.10.11 Therefore this does not affect the version of mod_nss package shipped with Red Hat Enterprise Linux 5, 6 and 7.
Statement: This issue did not affect the versions of mod_nss as shipped with Red Hat Enterprise Linux 5, 6 and 7.