References : 1205916 1207246 1207248 1208138 CVE-2023-0767 CVE-2023-21835
CVE-2023-21843
1208138,CVE-2023-0767
This update for mozilla-nss fixes the following issues:
Updated to NSS 3.79.4 (bsc#1208138):
- CVE-2023-0767: Fixed handling of unknown PKCS#12 safe bag types.
1205916,1207246,1207248,CVE-2023-21835,CVE-2023-21843
This update for java-17-openjdk fixes the following issues:
Updated to version jdk-17.0.6.0+10:
- CVE-2023-21835: Fixed handshake DoS attack against DTLS connections (bsc#1207246).
- CVE-2023-21843: Fixed soundbank URL remote loading (bsc#1207248).
Bugfixes:
- Avoid calling C_GetInfo() too early, before cryptoki is initialized (bsc#1205916).
The following package changes have been done:
- libfreebl3-3.79.4-150400.3.26.1 updated
- libfreebl3-hmac-3.79.4-150400.3.26.1 updated
- mozilla-nss-certs-3.79.4-150400.3.26.1 updated
- libsoftokn3-3.79.4-150400.3.26.1 updated
- mozilla-nss-3.79.4-150400.3.26.1 updated
- libsoftokn3-hmac-3.79.4-150400.3.26.1 updated
- java-17-openjdk-headless-17.0.6.0-150400.3.12.1 updated
- java-17-openjdk-17.0.6.0-150400.3.12.1 updated