Debian: DSA-5353-1: nss security update | LinuxSecurity.com

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5353-1                   [email protected]
https://www.debian.org/security/                     Salvatore Bonaccorso
February 17, 2023                     https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : nss
CVE ID         : CVE-2023-0767

Christian Holler discovered that incorrect handling of PKCS 12 Safe Bag
attributes in nss, the Mozilla Network Security Service library, may
result in execution of arbitrary code if a specially crafted PKCS 12
certificate bundle is processed.

For the stable distribution (bullseye), this problem has been fixed in
version 2:3.61-1+deb11u3.

We recommend that you upgrade your nss packages.

For the detailed security status of nss please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/nss

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]

Debian: DSA-5353-1: nss security update

February 17, 2023
Christian Holler discovered that incorrect handling of PKCS 12 Safe Bag attributes in nss, the Mozilla Network Security Service library, may result in execution of arbitrary code i...

Summary

For the stable distribution (bullseye), this problem has been fixed in
version 2:3.61-1+deb11u3.

We recommend that you upgrade your nss packages.

For the detailed security status of nss please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/nss

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]

Severity
Christian Holler discovered that incorrect handling of PKCS 12 Safe Bag
attributes in nss, the Mozilla Network Security Service library, may
result in execution of arbitrary code if a specially crafted PKCS 12
certificate bundle is processed.

We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.