Home
Reading
Searching
Subscribe
Sponsors
Statistics
Posting
Contact
Spam
Lists
Links
About
Hosting
Filtering
Features Download
Marketing
Archives
FAQ
Blog
 
Gmane
From: <riehecky-13hema8v3vg <at> public.gmane.org>
Subject: Security ERRATA Moderate: nss, nspr, and nss-util on SL6.x i386/x86_64
Newsgroups: gmane.linux.scientific.errata
Date: Wednesday 18th July 2012 16:36:34 UTC (over 4 years ago)
Synopsis:    Moderate: nss, nspr, and nss-util security, bug fix, and
enhancement update
Issue Date:  2012-07-17
CVE Numbers: CVE-2012-0441


Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.

A flaw was found in the way the ASN.1 (Abstract Syntax Notation One)
decoder in NSS handled zero length items. This flaw could cause the decoder
to incorrectly skip or replace certain items with a default value, or could
cause an application to crash if, for example, it received a
specially-crafted OCSP (Online Certificate Status Protocol) response.
(CVE-2012-0441)

The nspr package has been upgraded to upstream version 4.9.1, which
provides a number of bug fixes and enhancements over the previous version.

The nss-util package has been upgraded to upstream version 3.13.5, which
provides a number of bug fixes and enhancements over the previous version.

The nss package has been upgraded to upstream version 3.13.5, which
provides a number of bug fixes and enhancements over the previous version.

All NSS, NSPR, and nss-util users are advised to upgrade to these updated
packages, which correct these issues and add these enhancements. After
installing this update, applications using NSS, NSPR, or nss-util must be
restarted for this update to take effect.

SL6:
  i386
     nspr-4.9.1-2.el6_3.i686.rpm
     nspr-debuginfo-4.9.1-2.el6_3.i686.rpm
     nspr-devel-4.9.1-2.el6_3.i686.rpm
     nss-3.13.5-1.el6_3.i686.rpm
     nss-debuginfo-3.13.5-1.el6_3.i686.rpm
     nss-devel-3.13.5-1.el6_3.i686.rpm
     nss-pkcs11-devel-3.13.5-1.el6_3.i686.rpm
     nss-sysinit-3.13.5-1.el6_3.i686.rpm
     nss-tools-3.13.5-1.el6_3.i686.rpm
     nss-util-3.13.5-1.el6_3.i686.rpm
     nss-util-debuginfo-3.13.5-1.el6_3.i686.rpm
     nss-util-devel-3.13.5-1.el6_3.i686.rpm
  x86_64
     nspr-4.9.1-2.el6_3.i686.rpm
     nspr-4.9.1-2.el6_3.x86_64.rpm
     nspr-debuginfo-4.9.1-2.el6_3.i686.rpm
     nspr-debuginfo-4.9.1-2.el6_3.x86_64.rpm
     nspr-devel-4.9.1-2.el6_3.i686.rpm
     nspr-devel-4.9.1-2.el6_3.x86_64.rpm
     nss-3.13.5-1.el6_3.i686.rpm
     nss-3.13.5-1.el6_3.x86_64.rpm
     nss-debuginfo-3.13.5-1.el6_3.i686.rpm
     nss-debuginfo-3.13.5-1.el6_3.x86_64.rpm
     nss-devel-3.13.5-1.el6_3.i686.rpm
     nss-devel-3.13.5-1.el6_3.x86_64.rpm
     nss-pkcs11-devel-3.13.5-1.el6_3.i686.rpm
     nss-pkcs11-devel-3.13.5-1.el6_3.x86_64.rpm
     nss-sysinit-3.13.5-1.el6_3.x86_64.rpm
     nss-tools-3.13.5-1.el6_3.x86_64.rpm
     nss-util-3.13.5-1.el6_3.i686.rpm
     nss-util-3.13.5-1.el6_3.x86_64.rpm
     nss-util-debuginfo-3.13.5-1.el6_3.i686.rpm
     nss-util-debuginfo-3.13.5-1.el6_3.x86_64.rpm
     nss-util-devel-3.13.5-1.el6_3.i686.rpm
     nss-util-devel-3.13.5-1.el6_3.x86_64.rpm

- Scientific Linux Development Team
 
CD: 4ms