Debian: DSA-2490-1: nss security update
Debian: DSA-2490-1: nss security update
Kaspar Brand discovered that Mozilla's Network Security Services (NSS) library did insufficient length checking in the QuickDER decoder, allowing to crash a program using the library.
- ------------------------------------------------------------------------- Debian Security Advisory DSA-2490-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Thijs Kinkhorst June 7, 2012 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : nss Vulnerability : denial of service Problem type : remote Debian-specific: no CVE ID : CVE-2012-0441 Kaspar Brand discovered that Mozilla's Network Security Services (NSS) library did insufficient length checking in the QuickDER decoder, allowing to crash a program using the library. For the stable distribution (squeeze), this problem has been fixed in version 3.12.8-1+squeeze5. For the testing distribution (wheezy) and unstable distribution (sid), this problem has been fixed in version 2:3.13.4-3. We recommend that you upgrade your nss packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it.