Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 418
Alerts This Week
Warning Icon 1 418

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 3 articles for you...
202

openSUSE 15.4: SUSE-SU-2024:0597-1 critical: TLS Timing Attack

This update for mozilla-nss fixes the following issues: Update to NSS 3.90.2:. # Security update for mozilla-nss Announcement ID: SUSE-SU-2024:0597-1 Rating: important References: * bsc#1216198 Cross-References: * CVE-2023-5388 CVSS scores: * CVE-2023-5388 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * openSUSE Leap Micro 5.3 * openSUSE Leap Micro 5.4 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for mozilla-nss fixes the following issues: Update to NSS 3.90.2: * CVE-2023-5388: Fixed timing attack against RSA decryption in TLS (bsc#1216198) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2024-597=1 * openSUSE Leap Micro 5.3 zypper in -t patchopenSUSE-Leap-Micro-5.3-2024-597=1 * openSUSE Leap Micro 5.4 zypper in -t patch openSUSE-Leap-Micro-5.4-2024-597=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-597=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-597=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-597=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-597=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-597=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-597=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-597=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-597=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-597=1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLED-15-SP4-LTSS-2024-597=1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2024-597=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-597=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2024-597=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-2024-597=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2024-597=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * mozilla-nss-sysinit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-sysinit-3.90.2-150400.3.39.1 * mozilla-nss-debuginfo-3.90.2-150400.3.39.1 *libsoftokn3-3.90.2-150400.3.39.1 * libfreebl3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-debugsource-3.90.2-150400.3.39.1 * mozilla-nss-3.90.2-150400.3.39.1 * libfreebl3-3.90.2-150400.3.39.1 * libsoftokn3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-devel-3.90.2-150400.3.39.1 * mozilla-nss-certs-3.90.2-150400.3.39.1 * mozilla-nss-certs-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-tools-3.90.2-150400.3.39.1 * mozilla-nss-tools-debuginfo-3.90.2-150400.3.39.1 * openSUSE Leap 15.4 (x86_64) * mozilla-nss-32bit-3.90.2-150400.3.39.1 * mozilla-nss-certs-32bit-3.90.2-150400.3.39.1 * libsoftokn3-32bit-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-32bit-3.90.2-150400.3.39.1 * mozilla-nss-sysinit-32bit-debuginfo-3.90.2-150400.3.39.1 * libfreebl3-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-certs-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-sysinit-32bit-3.90.2-150400.3.39.1 * mozilla-nss-32bit-debuginfo-3.90.2-150400.3.39.1 * libfreebl3-32bit-3.90.2-150400.3.39.1 * openSUSE Leap 15.4 (aarch64_ilp32) * mozilla-nss-sysinit-64bit-3.90.2-150400.3.39.1 * mozilla-nss-sysinit-64bit-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-64bit-3.90.2-150400.3.39.1 * mozilla-nss-certs-64bit-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-64bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-certs-64bit-3.90.2-150400.3.39.1 * libfreebl3-64bit-3.90.2-150400.3.39.1 * libfreebl3-64bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-64bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-64bit-3.90.2-150400.3.39.1 * openSUSE Leap Micro 5.3 (aarch64 x86_64) * mozilla-nss-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-3.90.2-150400.3.39.1 * libfreebl3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-debugsource-3.90.2-150400.3.39.1 * mozilla-nss-3.90.2-150400.3.39.1 * libfreebl3-3.90.2-150400.3.39.1 * libsoftokn3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-certs-3.90.2-150400.3.39.1 *mozilla-nss-certs-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-tools-3.90.2-150400.3.39.1 * mozilla-nss-tools-debuginfo-3.90.2-150400.3.39.1 * openSUSE Leap Micro 5.4 (aarch64 s390x x86_64) * mozilla-nss-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-3.90.2-150400.3.39.1 * libfreebl3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-debugsource-3.90.2-150400.3.39.1 * mozilla-nss-3.90.2-150400.3.39.1 * libfreebl3-3.90.2-150400.3.39.1 * libsoftokn3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-certs-3.90.2-150400.3.39.1 * mozilla-nss-certs-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-tools-3.90.2-150400.3.39.1 * mozilla-nss-tools-debuginfo-3.90.2-150400.3.39.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * mozilla-nss-sysinit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-sysinit-3.90.2-150400.3.39.1 * mozilla-nss-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-3.90.2-150400.3.39.1 * libfreebl3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-debugsource-3.90.2-150400.3.39.1 * mozilla-nss-3.90.2-150400.3.39.1 * libfreebl3-3.90.2-150400.3.39.1 * libsoftokn3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-devel-3.90.2-150400.3.39.1 * mozilla-nss-certs-3.90.2-150400.3.39.1 * mozilla-nss-certs-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-tools-3.90.2-150400.3.39.1 * mozilla-nss-tools-debuginfo-3.90.2-150400.3.39.1 * openSUSE Leap 15.5 (x86_64) * mozilla-nss-32bit-3.90.2-150400.3.39.1 * mozilla-nss-certs-32bit-3.90.2-150400.3.39.1 * libsoftokn3-32bit-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-32bit-3.90.2-150400.3.39.1 * mozilla-nss-sysinit-32bit-debuginfo-3.90.2-150400.3.39.1 * libfreebl3-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-certs-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-sysinit-32bit-3.90.2-150400.3.39.1 * mozilla-nss-32bit-debuginfo-3.90.2-150400.3.39.1 * libfreebl3-32bit-3.90.2-150400.3.39.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64s390x x86_64) * mozilla-nss-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-3.90.2-150400.3.39.1 * libfreebl3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-debugsource-3.90.2-150400.3.39.1 * mozilla-nss-3.90.2-150400.3.39.1 * libfreebl3-3.90.2-150400.3.39.1 * libsoftokn3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-certs-3.90.2-150400.3.39.1 * mozilla-nss-certs-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-tools-3.90.2-150400.3.39.1 * mozilla-nss-tools-debuginfo-3.90.2-150400.3.39.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * mozilla-nss-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-3.90.2-150400.3.39.1 * libfreebl3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-debugsource-3.90.2-150400.3.39.1 * mozilla-nss-3.90.2-150400.3.39.1 * libfreebl3-3.90.2-150400.3.39.1 * libsoftokn3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-certs-3.90.2-150400.3.39.1 * mozilla-nss-certs-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-tools-3.90.2-150400.3.39.1 * mozilla-nss-tools-debuginfo-3.90.2-150400.3.39.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * mozilla-nss-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-3.90.2-150400.3.39.1 * libfreebl3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-debugsource-3.90.2-150400.3.39.1 * mozilla-nss-3.90.2-150400.3.39.1 * libfreebl3-3.90.2-150400.3.39.1 * libsoftokn3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-certs-3.90.2-150400.3.39.1 * mozilla-nss-certs-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-tools-3.90.2-150400.3.39.1 * mozilla-nss-tools-debuginfo-3.90.2-150400.3.39.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * mozilla-nss-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-3.90.2-150400.3.39.1 * libfreebl3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-debugsource-3.90.2-150400.3.39.1 * mozilla-nss-3.90.2-150400.3.39.1 * libfreebl3-3.90.2-150400.3.39.1 *libsoftokn3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-certs-3.90.2-150400.3.39.1 * mozilla-nss-certs-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-tools-3.90.2-150400.3.39.1 * mozilla-nss-tools-debuginfo-3.90.2-150400.3.39.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 s390x x86_64) * mozilla-nss-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-3.90.2-150400.3.39.1 * libfreebl3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-debugsource-3.90.2-150400.3.39.1 * mozilla-nss-3.90.2-150400.3.39.1 * libfreebl3-3.90.2-150400.3.39.1 * libsoftokn3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-certs-3.90.2-150400.3.39.1 * mozilla-nss-certs-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-tools-3.90.2-150400.3.39.1 * mozilla-nss-tools-debuginfo-3.90.2-150400.3.39.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * mozilla-nss-sysinit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-sysinit-3.90.2-150400.3.39.1 * mozilla-nss-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-3.90.2-150400.3.39.1 * libfreebl3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-debugsource-3.90.2-150400.3.39.1 * mozilla-nss-3.90.2-150400.3.39.1 * libfreebl3-3.90.2-150400.3.39.1 * libsoftokn3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-devel-3.90.2-150400.3.39.1 * mozilla-nss-certs-3.90.2-150400.3.39.1 * mozilla-nss-certs-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-tools-3.90.2-150400.3.39.1 * mozilla-nss-tools-debuginfo-3.90.2-150400.3.39.1 * Basesystem Module 15-SP5 (x86_64) * mozilla-nss-32bit-3.90.2-150400.3.39.1 * mozilla-nss-certs-32bit-3.90.2-150400.3.39.1 * libsoftokn3-32bit-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-32bit-3.90.2-150400.3.39.1 * libfreebl3-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-certs-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-32bit-debuginfo-3.90.2-150400.3.39.1 * libfreebl3-32bit-3.90.2-150400.3.39.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15SP4 (aarch64 x86_64) * mozilla-nss-sysinit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-sysinit-3.90.2-150400.3.39.1 * mozilla-nss-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-3.90.2-150400.3.39.1 * libfreebl3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-debugsource-3.90.2-150400.3.39.1 * mozilla-nss-3.90.2-150400.3.39.1 * libfreebl3-3.90.2-150400.3.39.1 * libsoftokn3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-devel-3.90.2-150400.3.39.1 * mozilla-nss-certs-3.90.2-150400.3.39.1 * mozilla-nss-certs-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-tools-3.90.2-150400.3.39.1 * mozilla-nss-tools-debuginfo-3.90.2-150400.3.39.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * mozilla-nss-32bit-3.90.2-150400.3.39.1 * mozilla-nss-certs-32bit-3.90.2-150400.3.39.1 * libsoftokn3-32bit-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-32bit-3.90.2-150400.3.39.1 * libfreebl3-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-certs-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-32bit-debuginfo-3.90.2-150400.3.39.1 * libfreebl3-32bit-3.90.2-150400.3.39.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * mozilla-nss-sysinit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-sysinit-3.90.2-150400.3.39.1 * mozilla-nss-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-3.90.2-150400.3.39.1 * libfreebl3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-debugsource-3.90.2-150400.3.39.1 * mozilla-nss-3.90.2-150400.3.39.1 * libfreebl3-3.90.2-150400.3.39.1 * libsoftokn3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-devel-3.90.2-150400.3.39.1 * mozilla-nss-certs-3.90.2-150400.3.39.1 * mozilla-nss-certs-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-tools-3.90.2-150400.3.39.1 * mozilla-nss-tools-debuginfo-3.90.2-150400.3.39.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * mozilla-nss-32bit-3.90.2-150400.3.39.1 *mozilla-nss-certs-32bit-3.90.2-150400.3.39.1 * libsoftokn3-32bit-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-32bit-3.90.2-150400.3.39.1 * libfreebl3-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-certs-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-32bit-debuginfo-3.90.2-150400.3.39.1 * libfreebl3-32bit-3.90.2-150400.3.39.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (x86_64) * libsoftokn3-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-sysinit-3.90.2-150400.3.39.1 * libfreebl3-3.90.2-150400.3.39.1 * mozilla-nss-tools-3.90.2-150400.3.39.1 * mozilla-nss-certs-32bit-3.90.2-150400.3.39.1 * mozilla-nss-sysinit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-certs-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-debuginfo-3.90.2-150400.3.39.1 * libfreebl3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-3.90.2-150400.3.39.1 * mozilla-nss-devel-3.90.2-150400.3.39.1 * libsoftokn3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-tools-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-32bit-3.90.2-150400.3.39.1 * mozilla-nss-debugsource-3.90.2-150400.3.39.1 * mozilla-nss-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-certs-3.90.2-150400.3.39.1 * mozilla-nss-32bit-3.90.2-150400.3.39.1 * libfreebl3-32bit-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-3.90.2-150400.3.39.1 * libfreebl3-32bit-3.90.2-150400.3.39.1 * mozilla-nss-certs-debuginfo-3.90.2-150400.3.39.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (aarch64 ppc64le s390x x86_64) * mozilla-nss-sysinit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-sysinit-3.90.2-150400.3.39.1 * mozilla-nss-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-3.90.2-150400.3.39.1 * libfreebl3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-debugsource-3.90.2-150400.3.39.1 * mozilla-nss-3.90.2-150400.3.39.1 * libfreebl3-3.90.2-150400.3.39.1 * libsoftokn3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-devel-3.90.2-150400.3.39.1 *mozilla-nss-certs-3.90.2-150400.3.39.1 * mozilla-nss-certs-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-tools-3.90.2-150400.3.39.1 * mozilla-nss-tools-debuginfo-3.90.2-150400.3.39.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (x86_64) * mozilla-nss-32bit-3.90.2-150400.3.39.1 * mozilla-nss-certs-32bit-3.90.2-150400.3.39.1 * libsoftokn3-32bit-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-32bit-3.90.2-150400.3.39.1 * libfreebl3-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-certs-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-32bit-debuginfo-3.90.2-150400.3.39.1 * libfreebl3-32bit-3.90.2-150400.3.39.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * mozilla-nss-sysinit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-sysinit-3.90.2-150400.3.39.1 * mozilla-nss-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-3.90.2-150400.3.39.1 * libfreebl3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-debugsource-3.90.2-150400.3.39.1 * mozilla-nss-3.90.2-150400.3.39.1 * libfreebl3-3.90.2-150400.3.39.1 * libsoftokn3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-devel-3.90.2-150400.3.39.1 * mozilla-nss-certs-3.90.2-150400.3.39.1 * mozilla-nss-certs-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-tools-3.90.2-150400.3.39.1 * mozilla-nss-tools-debuginfo-3.90.2-150400.3.39.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * mozilla-nss-32bit-3.90.2-150400.3.39.1 * mozilla-nss-certs-32bit-3.90.2-150400.3.39.1 * libsoftokn3-32bit-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-32bit-3.90.2-150400.3.39.1 * libfreebl3-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-certs-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-32bit-debuginfo-3.90.2-150400.3.39.1 * libfreebl3-32bit-3.90.2-150400.3.39.1 * SUSE Manager Proxy 4.3 (x86_64) * libsoftokn3-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-sysinit-3.90.2-150400.3.39.1 *libfreebl3-3.90.2-150400.3.39.1 * mozilla-nss-tools-3.90.2-150400.3.39.1 * mozilla-nss-certs-32bit-3.90.2-150400.3.39.1 * mozilla-nss-sysinit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-certs-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-debuginfo-3.90.2-150400.3.39.1 * libfreebl3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-3.90.2-150400.3.39.1 * mozilla-nss-devel-3.90.2-150400.3.39.1 * libsoftokn3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-tools-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-32bit-3.90.2-150400.3.39.1 * mozilla-nss-debugsource-3.90.2-150400.3.39.1 * mozilla-nss-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-certs-3.90.2-150400.3.39.1 * mozilla-nss-32bit-3.90.2-150400.3.39.1 * libfreebl3-32bit-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-3.90.2-150400.3.39.1 * libfreebl3-32bit-3.90.2-150400.3.39.1 * mozilla-nss-certs-debuginfo-3.90.2-150400.3.39.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * libsoftokn3-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-sysinit-3.90.2-150400.3.39.1 * libfreebl3-3.90.2-150400.3.39.1 * mozilla-nss-tools-3.90.2-150400.3.39.1 * mozilla-nss-certs-32bit-3.90.2-150400.3.39.1 * mozilla-nss-sysinit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-certs-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-debuginfo-3.90.2-150400.3.39.1 * libfreebl3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-3.90.2-150400.3.39.1 * mozilla-nss-devel-3.90.2-150400.3.39.1 * libsoftokn3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-tools-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-32bit-3.90.2-150400.3.39.1 * mozilla-nss-debugsource-3.90.2-150400.3.39.1 * mozilla-nss-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-certs-3.90.2-150400.3.39.1 * mozilla-nss-32bit-3.90.2-150400.3.39.1 * libfreebl3-32bit-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-3.90.2-150400.3.39.1 * libfreebl3-32bit-3.90.2-150400.3.39.1 *mozilla-nss-certs-debuginfo-3.90.2-150400.3.39.1 * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * mozilla-nss-sysinit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-sysinit-3.90.2-150400.3.39.1 * mozilla-nss-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-3.90.2-150400.3.39.1 * libfreebl3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-debugsource-3.90.2-150400.3.39.1 * mozilla-nss-3.90.2-150400.3.39.1 * libfreebl3-3.90.2-150400.3.39.1 * libsoftokn3-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-devel-3.90.2-150400.3.39.1 * mozilla-nss-certs-3.90.2-150400.3.39.1 * mozilla-nss-certs-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-tools-3.90.2-150400.3.39.1 * mozilla-nss-tools-debuginfo-3.90.2-150400.3.39.1 * SUSE Manager Server 4.3 (x86_64) * mozilla-nss-32bit-3.90.2-150400.3.39.1 * mozilla-nss-certs-32bit-3.90.2-150400.3.39.1 * libsoftokn3-32bit-debuginfo-3.90.2-150400.3.39.1 * libsoftokn3-32bit-3.90.2-150400.3.39.1 * libfreebl3-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-certs-32bit-debuginfo-3.90.2-150400.3.39.1 * mozilla-nss-32bit-debuginfo-3.90.2-150400.3.39.1 * libfreebl3-32bit-3.90.2-150400.3.39.1 ## References: * https://www.suse.com/security/cve/CVE-2023-5388.html * https://bugzilla.suse.com/show_bug.cgi?id=1216198 . Critical enhancement release for Mozilla NSS addressing a vulnerability related to timing exploitation affecting TLS decryption on openSUSE systems.. SUSE Security Advisory,TLS Timing Attack,mozilla nss update,openSUSE Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 22, 2024 Important OpenSUSE
100

SUSE: 2024:0578-1 Important: Fix For Mozilla NSS Timing Attack

* bsc#1216198 Cross-References: * CVE-2023-5388 . # Security update for mozilla-nss Announcement ID: SUSE-SU-2024:0578-1 Rating: important References: * bsc#1216198 Cross-References: * CVE-2023-5388 CVSS scores: * CVE-2023-5388 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for mozilla-nss fixes the following issues: Update to NSS 3.90.2: * CVE-2023-5388: Fixed timing attack against RSA decryption in TLS (bsc#1216198) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-578=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-578=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-578=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-578=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * mozilla-nss-devel-3.90.2-58.111.1 * mozilla-nss-debugsource-3.90.2-58.111.1 * mozilla-nss-debuginfo-3.90.2-58.111.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * mozilla-nss-certs-3.90.2-58.111.1 * mozilla-nss-debugsource-3.90.2-58.111.1 * mozilla-nss-certs-debuginfo-3.90.2-58.111.1 * mozilla-nss-devel-3.90.2-58.111.1 * mozilla-nss-sysinit-3.90.2-58.111.1 *mozilla-nss-tools-3.90.2-58.111.1 * mozilla-nss-tools-debuginfo-3.90.2-58.111.1 * libfreebl3-debuginfo-3.90.2-58.111.1 * mozilla-nss-3.90.2-58.111.1 * mozilla-nss-debuginfo-3.90.2-58.111.1 * mozilla-nss-sysinit-debuginfo-3.90.2-58.111.1 * libfreebl3-3.90.2-58.111.1 * libsoftokn3-3.90.2-58.111.1 * libsoftokn3-debuginfo-3.90.2-58.111.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (x86_64) * mozilla-nss-debuginfo-32bit-3.90.2-58.111.1 * mozilla-nss-sysinit-debuginfo-32bit-3.90.2-58.111.1 * mozilla-nss-certs-debuginfo-32bit-3.90.2-58.111.1 * libsoftokn3-debuginfo-32bit-3.90.2-58.111.1 * libfreebl3-debuginfo-32bit-3.90.2-58.111.1 * mozilla-nss-certs-32bit-3.90.2-58.111.1 * libsoftokn3-32bit-3.90.2-58.111.1 * mozilla-nss-sysinit-32bit-3.90.2-58.111.1 * libfreebl3-32bit-3.90.2-58.111.1 * mozilla-nss-32bit-3.90.2-58.111.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * mozilla-nss-certs-3.90.2-58.111.1 * mozilla-nss-debugsource-3.90.2-58.111.1 * mozilla-nss-certs-debuginfo-3.90.2-58.111.1 * mozilla-nss-devel-3.90.2-58.111.1 * mozilla-nss-sysinit-3.90.2-58.111.1 * mozilla-nss-tools-3.90.2-58.111.1 * mozilla-nss-tools-debuginfo-3.90.2-58.111.1 * libfreebl3-debuginfo-3.90.2-58.111.1 * mozilla-nss-3.90.2-58.111.1 * mozilla-nss-debuginfo-3.90.2-58.111.1 * mozilla-nss-sysinit-debuginfo-3.90.2-58.111.1 * libfreebl3-3.90.2-58.111.1 * libsoftokn3-3.90.2-58.111.1 * libsoftokn3-debuginfo-3.90.2-58.111.1 * SUSE Linux Enterprise Server 12 SP5 (s390x x86_64) * mozilla-nss-debuginfo-32bit-3.90.2-58.111.1 * mozilla-nss-sysinit-debuginfo-32bit-3.90.2-58.111.1 * mozilla-nss-certs-debuginfo-32bit-3.90.2-58.111.1 * libsoftokn3-debuginfo-32bit-3.90.2-58.111.1 * libfreebl3-debuginfo-32bit-3.90.2-58.111.1 * mozilla-nss-certs-32bit-3.90.2-58.111.1 * libsoftokn3-32bit-3.90.2-58.111.1 * mozilla-nss-sysinit-32bit-3.90.2-58.111.1 *libfreebl3-32bit-3.90.2-58.111.1 * mozilla-nss-32bit-3.90.2-58.111.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * mozilla-nss-certs-3.90.2-58.111.1 * mozilla-nss-debugsource-3.90.2-58.111.1 * mozilla-nss-certs-debuginfo-3.90.2-58.111.1 * mozilla-nss-devel-3.90.2-58.111.1 * mozilla-nss-sysinit-3.90.2-58.111.1 * mozilla-nss-tools-3.90.2-58.111.1 * mozilla-nss-tools-debuginfo-3.90.2-58.111.1 * libfreebl3-debuginfo-3.90.2-58.111.1 * mozilla-nss-3.90.2-58.111.1 * mozilla-nss-debuginfo-3.90.2-58.111.1 * mozilla-nss-sysinit-debuginfo-3.90.2-58.111.1 * libfreebl3-3.90.2-58.111.1 * libsoftokn3-3.90.2-58.111.1 * libsoftokn3-debuginfo-3.90.2-58.111.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (x86_64) * mozilla-nss-debuginfo-32bit-3.90.2-58.111.1 * mozilla-nss-sysinit-debuginfo-32bit-3.90.2-58.111.1 * mozilla-nss-certs-debuginfo-32bit-3.90.2-58.111.1 * libsoftokn3-debuginfo-32bit-3.90.2-58.111.1 * libfreebl3-debuginfo-32bit-3.90.2-58.111.1 * mozilla-nss-certs-32bit-3.90.2-58.111.1 * libsoftokn3-32bit-3.90.2-58.111.1 * mozilla-nss-sysinit-32bit-3.90.2-58.111.1 * libfreebl3-32bit-3.90.2-58.111.1 * mozilla-nss-32bit-3.90.2-58.111.1 ## References: * https://www.suse.com/security/cve/CVE-2023-5388.html * https://bugzilla.suse.com/show_bug.cgi?id=1216198 . Security enhancement released for Mozilla NSS in SUSE, addressing vulnerabilities linked to timing attacks along with detailed installation guidelines.. Mozilla NSS, SUSE Security, Timing Attack, Linux Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 21, 2024 Important SuSE
100

SUSE: 2023:388-1 Important: Mozilla NSS Security Update for suse/pcp

The container suse/pcp was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/pcp ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:388-1 Container Tags : suse/pcp:5 , suse/pcp:5-12.27 , suse/pcp:5.2 , suse/pcp:5.2-12.27 , suse/pcp:5.2.2 , suse/pcp:5.2.2-12.27 , suse/pcp:latest Container Release : 12.27 Severity : important Type : security References : 1208138 CVE-2023-0767 ----------------------------------------------------------------- The container suse/pcp was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:434-1 Released: Thu Feb 16 09:08:05 2023 Summary: Security update for mozilla-nss Type: security Severity: important References: 1208138,CVE-2023-0767 This update for mozilla-nss fixes the following issues: Updated to NSS 3.79.4 (bsc#1208138): - CVE-2023-0767: Fixed handling of unknown PKCS#12 safe bag types. The following package changes have been done: - libfreebl3-3.79.4-150400.3.26.1 updated - libfreebl3-hmac-3.79.4-150400.3.26.1 updated - mozilla-nss-certs-3.79.4-150400.3.26.1 updated - libsoftokn3-3.79.4-150400.3.26.1 updated - mozilla-nss-3.79.4-150400.3.26.1 updated - libsoftokn3-hmac-3.79.4-150400.3.26.1 updated . SUSE has released vital security patches for the container suse/pcp, targeting significant vulnerabilities to bolster system protection and reliability.. SUSE Container Security, SUSE PCP Update, NSS Security Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 17, 2023 Important SuSE
91

Gentoo GLSA-202212-05: High Severity Mozilla NSS Risks for Code Execution

Multiple vulnerabilities have been discovered in NSS, the worst of which could result in arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202212-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Mozilla Network Security Service (NSS): Multiple Vulnerabilities Date: December 19, 2022 Bugs: #827946, #836386, #848984, #877169 ID: 202212-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been discovered in NSS, the worst of which could result in arbitrary code execution. Background ========= The Mozilla Network Security Service is a library implementing security features like SSL v.2/v.3, TLS, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME and X.509 certificates. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-libs/nss < 3.79.2 > = 3.79.2 Description ========== Multiple vulnerabilities have been discovered in Mozilla Network Security Service (NSS). Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Mozilla Network Security Service (NSS) users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/nss-3.79.2" References ========= [ 1 ] CVE-2021-43527 https://nvd.nist.gov/vuln/detail/CVE-2021-43527 [ 2 ] CVE-2022-1097 https://nvd.nist.gov/vuln/detail/CVE-2022-1097 [ 3 ] CVE-2022-3479 https://nvd.nist.gov/vuln/detail/CVE-2022-3479 [ 4 ] MFSA-2021-51 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202212-05 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2022 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . The recent Gentoo GLSA 202212-05 report highlights several critical vulnerabilities within NSS, which present significant threats such as the potential for arbitrary code execution.. Mozilla Security,NSS Issues,Gentoo Advisory,Code Execution Risks,Security Updates. . LinuxSecurity.com Team

Calendar%202 Dec 19, 2022 Gentoo
100

SUSE: 2022:14936-1 Important: Mozilla NSS Memory Safety Issue Fix

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for mozilla-nss ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:14936-1 Rating: important References: #1197903 Cross-References: CVE-2022-1097 Affected Products: SUSE Linux Enterprise Debuginfo 11-SP3 SUSE Linux Enterprise Debuginfo 11-SP4 SUSE Linux Enterprise Point of Sale 11-SP3 SUSE Linux Enterprise Server 11-SP4-LTSS ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for mozilla-nss fixes the following issues: Mozilla NSS 3.68.3 (bsc#1197903): - CVE-2022-1097: Fixed memory safety violations that could occur when PKCS#11 tokens are removed while in use. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4-LTSS: zypper in -t patch slessp4-mozilla-nss-14936=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-mozilla-nss-14936=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-mozilla-nss-14936=1 - SUSE Linux Enterprise Debuginfo 11-SP3: zypper in -t patch dbgsp3-mozilla-nss-14936=1 Package List: - SUSE Linux Enterprise Server 11-SP4-LTSS (i586 ppc64 s390x x86_64): libfreebl3-3.68.3-47.25.1 libsoftokn3-3.68.3-47.25.1 mozilla-nss-3.68.3-47.25.1 mozilla-nss-certs-3.68.3-47.25.1 mozilla-nss-devel-3.68.3-47.25.1 mozilla-nss-tools-3.68.3-47.25.1 - SUSE Linux Enterprise Server 11-SP4-LTSS (ppc64 s390x x86_64): libfreebl3-32bit-3.68.3-47.25.1 libsoftokn3-32bit-3.68.3-47.25.1 mozilla-nss-32bit-3.68.3-47.25.1 mozilla-nss-certs-32bit-3.68.3-47.25.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (i586): libfreebl3-3.68.3-47.25.1 libsoftokn3-3.68.3-47.25.1 mozilla-nss-3.68.3-47.25.1 mozilla-nss-certs-3.68.3-47.25.1 mozilla-nss-tools-3.68.3-47.25.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ppc64 s390x x86_64): mozilla-nss-debuginfo-3.68.3-47.25.1 - SUSE Linux Enterprise Debuginfo 11-SP3 (i586 s390x x86_64): mozilla-nss-debuginfo-3.68.3-47.25.1 References: https://www.suse.com/security/cve/CVE-2022-1097.html https://bugzilla.suse.com/1197903 . This patch includes critical updates addressing vulnerabilities in Microsoft Defender, safeguarding your Ubuntu environment against potential threats.. SUSE Security Update, Mozilla NSS, Memory Safety, Threat Mitigation, System Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 05, 2022 Important SuSE
91

Gentoo: GLSA-202003-37 Normal Severity: Mozilla NSS Code Execution Threat

Multiple vulnerabilities have been found in Mozilla Network Security Service (NSS), the worst of which may lead to arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202003-37 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Mozilla Network Security Service: Multiple vulnerabilities Date: March 16, 2020 Bugs: #627534, #676868, #701840 ID: 202003-37 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Mozilla Network Security Service (NSS), the worst of which may lead to arbitrary code execution. Background ========= The Mozilla Network Security Service (NSS) is a library implementing security features like SSL v.2/v.3, TLS, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME and X.509 certificates. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-libs/nss < 3.49 > = 3.49 Description ========== Multiple vulnerabilities have been discovered in Mozilla Network Security Service (NSS). Please review the CVE identifiers referenced below for details. Impact ===== An attacker could execute arbitrary code, cause a Denial of Service condition or have other unspecified impact. Workaround ========= There is no known workaround at this time. Resolution ========= All Mozilla Network Security Service (NSS) users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/nss-3.49" References ========= [ 1 ] CVE-2017-11695 https://nvd.nist.gov/vuln/detail/CVE-2017-11695 [ 2 ] CVE-2017-11696 https://nvd.nist.gov/vuln/detail/CVE-2017-11696 [ 3 ] CVE-2017-11697 https://nvd.nist.gov/vuln/detail/CVE-2017-11697 [ 4 ] CVE-2017-11698 https://nvd.nist.gov/vuln/detail/CVE-2017-11698 [ 5 ] CVE-2018-18508 https://nvd.nist.gov/vuln/detail/CVE-2018-18508 [ 6 ] CVE-2019-11745 https://nvd.nist.gov/vuln/detail/CVE-2019-11745 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202003-37 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2020 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Several weaknesses identified in Mozilla NSS might facilitate unauthorized code execution and trigger Denial of Service in Gentoo.. Mozilla NSS,Gentoo Security Advisory,Code Execution,Normal Severity. . LinuxSecurity.com Team

Calendar%202 Mar 16, 2020 Gentoo
202

openSUSE 13.1: 2016:2386-1 Important Mozilla Firefox and NSS Update

An update that fixes 18 vulnerabilities is now available. An update that fixes 18 vulnerabilities is now available. An update that fixes 18 vulnerabilities is now available.. openSUSE Security Update: Security update for MozillaFirefox, mozilla-nss ______________________________________________________________________________ Announcement ID: openSUSE-SU-2016:2386-1 Rating: important References: #999701 Cross-References: CVE-2016-2827 CVE-2016-5256 CVE-2016-5257 CVE-2016-5270 CVE-2016-5271 CVE-2016-5272 CVE-2016-5273 CVE-2016-5274 CVE-2016-5275 CVE-2016-5276 CVE-2016-5277 CVE-2016-5278 CVE-2016-5279 CVE-2016-5280 CVE-2016-5281 CVE-2016-5282 CVE-2016-5283 CVE-2016-5284 Affected Products: openSUSE 13.1 ______________________________________________________________________________ An update that fixes 18 vulnerabilities is now available. Description: MozillaFirefox was updated to version 49.0 (boo#999701) - New features * Updated Firefox Login Manager to allow HTTPS pages to use saved HTTP logins. * Added features to Reader Mode that make it easier on the eyes and the ears * Improved video performance for users on systems that support SSE3 without hardware acceleration * Added context menu controls to HTML5 audio and video that let users loops files or play files at 1.25x speed * Improvements in about:memory reports for tracking font memory usage - Security related fixes * MFSA 2016-85 CVE-2016-2827 (bmo#1289085) - Out-of-bounds read in mozilla::net::IsValidReferrerPolicy CVE-2016-5270 (bmo#1291016) - Heap-buffer-overflow in nsCaseTransformTextRunFactory::TransformString CVE-2016-5271 (bmo#1288946) - Out-of-bounds read in PropertyProvider::GetSpacingInternal CVE-2016-5272 (bmo#1297934) - Bad cast in nsImageGeometryMixin CVE-2016-5273 (bmo#1280387) -crash in mozilla::a11y::HyperTextAccessible::GetChildOffset CVE-2016-5276 (bmo#1287721) - Heap-use-after-free in mozilla::a11y::DocAccessible::ProcessInvalidationList CVE-2016-5274 (bmo#1282076) - use-after-free in nsFrameManager::CaptureFrameState CVE-2016-5277 (bmo#1291665) - Heap-use-after-free in nsRefreshDriver::Tick CVE-2016-5275 (bmo#1287316) - global-buffer-overflow in mozilla::gfx::FilterSupport::ComputeSourceNeededRegions CVE-2016-5278 (bmo#1294677) - Heap-buffer-overflow in nsBMPEncoder::AddImageFrame CVE-2016-5279 (bmo#1249522) - Full local path of files is available to web pages after drag and drop CVE-2016-5280 (bmo#1289970) - Use-after-free in mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap CVE-2016-5281 (bmo#1284690) - use-after-free in DOMSVGLength CVE-2016-5282 (bmo#932335) - Don't allow content to request favicons from non-whitelisted schemes CVE-2016-5283 (bmo#928187) - fragment timing attack can reveal cross-origin data CVE-2016-5284 (bmo#1303127) - Add-on update site certificate pin expiration CVE-2016-5256 - Memory safety bugs fixed in Firefox 49 CVE-2016-5257 - Memory safety bugs fixed in Firefox 49 and Firefox ESR 45.4 - requires NSS 3.25 - Mozilla Firefox 48.0.2: * Mitigate a startup crash issue caused on Windows (bmo#1291738) mozilla-nss was updated to NSS 3.25. New functionality: * Implemented DHE key agreement for TLS 1.3 * Added support for ChaCha with TLS 1.3 * Added support for TLS 1.2 ciphersuites that use SHA384 as the PRF * In previous versions, when using client authentication with TLS 1.2, NSS only supported certificate_verify messages that used the same signature hash algorithm as used by the PRF. This limitation has been removed. * Several functions have been added to the public API of the NSS Cryptoki Framework. New functions: * NSSCKFWSlot_GetSlotID * NSSCKFWSession_GetFWSlot *NSSCKFWInstance_DestroySessionHandle * NSSCKFWInstance_FindSessionHandle Notable changes: * An SSL socket can no longer be configured to allow both TLS 1.3 and SSLv3 * Regression fix: NSS no longer reports a failure if an application attempts to disable the SSLv2 protocol. * The list of trusted CA certificates has been updated to version 2.8 * The following CA certificate was Removed Sonera Class1 CA * The following CA certificates were Added Hellenic Academic and Research Institutions RootCA 2015 Hellenic Academic and Research Institutions ECC RootCA 2015 Certplus Root CA G1 Certplus Root CA G2 OpenTrust Root CA G1 OpenTrust Root CA G2 OpenTrust Root CA G3 Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 13.1: zypper in -t patch 2016-1128=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 13.1 (i586 x86_64): MozillaFirefox-49.0.1-125.2 MozillaFirefox-branding-upstream-49.0.1-125.2 MozillaFirefox-buildsymbols-49.0.1-125.2 MozillaFirefox-debuginfo-49.0.1-125.2 MozillaFirefox-debugsource-49.0.1-125.2 MozillaFirefox-devel-49.0.1-125.2 MozillaFirefox-translations-common-49.0.1-125.2 MozillaFirefox-translations-other-49.0.1-125.2 libfreebl3-3.25-91.1 libfreebl3-debuginfo-3.25-91.1 libsoftokn3-3.25-91.1 libsoftokn3-debuginfo-3.25-91.1 mozilla-nss-3.25-91.1 mozilla-nss-certs-3.25-91.1 mozilla-nss-certs-debuginfo-3.25-91.1 mozilla-nss-debuginfo-3.25-91.1 mozilla-nss-debugsource-3.25-91.1 mozilla-nss-devel-3.25-91.1 mozilla-nss-sysinit-3.25-91.1 mozilla-nss-sysinit-debuginfo-3.25-91.1 mozilla-nss-tools-3.25-91.1 mozilla-nss-tools-debuginfo-3.25-91.1 - openSUSE 13.1 (x86_64): libfreebl3-32bit-3.25-91.1 libfreebl3-debuginfo-32bit-3.25-91.1 libsoftokn3-32bit-3.25-91.1 libsoftokn3-debuginfo-32bit-3.25-91.1 mozilla-nss-32bit-3.25-91.1 mozilla-nss-certs-32bit-3.25-91.1 mozilla-nss-certs-debuginfo-32bit-3.25-91.1 mozilla-nss-debuginfo-32bit-3.25-91.1 mozilla-nss-sysinit-32bit-3.25-91.1 mozilla-nss-sysinit-debuginfo-32bit-3.25-91.1 References: https://www.suse.com/security/cve/CVE-2016-2827.html https://www.suse.com/security/cve/CVE-2016-5256.html https://www.suse.com/security/cve/CVE-2016-5257.html https://www.suse.com/security/cve/CVE-2016-5270.html https://www.suse.com/security/cve/CVE-2016-5271.html https://www.suse.com/security/cve/CVE-2016-5272.html https://www.suse.com/security/cve/CVE-2016-5273.html https://www.suse.com/security/cve/CVE-2016-5274.html https://www.suse.com/security/cve/CVE-2016-5275.html https://www.suse.com/security/cve/CVE-2016-5276.html https://www.suse.com/security/cve/CVE-2016-5277.html https://www.suse.com/security/cve/CVE-2016-5278.html https://www.suse.com/security/cve/CVE-2016-5279.html https://www.suse.com/security/cve/CVE-2016-5280.html https://www.suse.com/security/cve/CVE-2016-5281.html https://www.suse.com/security/cve/CVE-2016-5282.html https://www.suse.com/security/cve/CVE-2016-5283.html https://www.suse.com/security/cve/CVE-2016-5284.html https://bugzilla.suse.com/999701 . An urgent patch released for MozillaFirefox and mozilla-nss tackles 18 security flaws in openSUSE's newest system update.. MozillaFirefox Security, openSUSE Fix, Mozilla-nss Update, Memory Safety Patch, Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 26, 2016 Important OpenSUSE
100

SUSE 12 SP3: 2021:1304-1 Critical: Firefox SSL Certificate Weakness

An update that fixes one vulnerability is now available. It An update that fixes one vulnerability is now available. It An update that fixes one vulnerability is now available. It includes one version update. includes one version update.. SUSE Security Update: Security update for mozilla-nss ______________________________________________________________________________ Announcement ID: SUSE-SU-2014:1220-2 Rating: important References: #897890 Cross-References: CVE-2014-1568 Affected Products: SUSE Linux Enterprise Server 11 SP2 LTSS ______________________________________________________________________________ An update that fixes one vulnerability is now available. It includes one version update. Description: Mozilla NSS was updated to 3.16.5 to fix a RSA certificate forgery issue. MFSA 2014-73 / CVE-2014-1568: Antoine Delignat-Lavaud, security researcher at Inria Paris in team Prosecco, reported an issue in Network Security Services (NSS) libraries affecting all versions. He discovered that NSS is vulnerable to a variant of a signature forgery attack previously published by Daniel Bleichenbacher. This is due to lenient parsing of ASN.1 values involved in a signature and could lead to the forging of RSA certificates. The Advanced Threat Research team at Intel Security also independently discovered and reported this issue. Security Issues: * CVE-2014-1568 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11 SP2 LTSS: zypper in -t patch slessp2-libfreebl3-9774 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server 11 SP2 LTSS (i586 s390x x86_64) [New Version: 3.16.5]: libfreebl3-3.16.5-0.4.2.1 mozilla-nss-3.16.5-0.4.2.1 mozilla-nss-devel-3.16.5-0.4.2.1 mozilla-nss-tools-3.16.5-0.4.2.1 - SUSE Linux Enterprise Server 11 SP2 LTSS (s390x x86_64) [New Version: 3.16.5]: libfreebl3-32bit-3.16.5-0.4.2.1 mozilla-nss-32bit-3.16.5-0.4.2.1 References: https://www.suse.com/security/cve/CVE-2014-1568.html https://bugzilla.suse.com/show_bug.cgi?id=897890 https://scc.suse.com:443/patches/ . Critical patch released for SUSE: Mozilla NSS fixes RSA certificate spoofing issue. Vital upgrade for safeguarding systems.. SUSE Linux, Mozilla NSS, Security Patch, RSA Forgery, System Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 29, 2014 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200