security advisorycode executiondebian
Christian Holler discovered that incorrect handling of PKCS 12 Safe Bag attributes in nss, the Mozilla Network Security Service library, may result in execution of arbitrary code if a specially crafted PKCS 12 certificate bundle is processed. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5353-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso February 17, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : nss CVE ID : CVE-2023-0767 Christian Holler discovered that incorrect handling of PKCS 12 Safe Bag attributes in nss, the Mozilla Network Security Service library, may result in execution of arbitrary code if a specially crafted PKCS 12 certificate bundle is processed. For the stable distribution (bullseye), this problem has been fixed in version 2:3.61-1+deb11u3. We recommend that you upgrade your nss packages. For the detailed security status of nss please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/nss Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian DSA-5360-1 TLS security patch addresses a possible vulnerability in certificate validation that could allow unauthorized access.. nss security update, debian advisory, code execution risk. . Severity: Critical. LinuxSecurity.com Team
Feb 17, 2023
•Critical
Debian