Updates the nspr and nss packages to upstream NSPR 4.23 and NSS 3.47 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes - . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-8934d55352 2019-11-03 00:10:34.338305 --------------------------------------------------------------------------------Name : nspr Product : Fedora 30 Version : 4.23.0 Release : 1.fc30 URL : https://firefox-source-docs.mozilla.org/nspr/index.html Summary : Netscape Portable Runtime Description : NSPR provides platform independence for non-GUI operating system facilities. These facilities include threads, thread synchronization, normal file and network I/O, interval timing and calendar time, basic memory management (malloc and free) and shared library linking. --------------------------------------------------------------------------------Update Information: Updates the nspr and nss packages to upstream NSPR 4.23 and NSS 3.47 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes ---------------------------------------------------------------------------------ChangeLog: * Fri Oct 18 2019 Daiki Ueno - 4.23.0-1 - Update to NSPR 4.23 * Tue Sep 3 2019 Daiki Ueno - 4.22.0-1 - Update to NSPR 4.22 --------------------------------------------------------------------------------References: [ 1 ] Bug #1757995 - nss-3.47 is available https://bugzilla.redhat.com/show_bug.cgi?id=1757995 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-8934d55352' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with theFedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Updated nss, nspr, and nss-util packages that fix multiple security issues are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Important: nss, nspr, and nss-util security update Advisory ID: RHSA-2013:1829-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2013:1829.html Issue date: 2013-12-12 CVE Names: CVE-2013-1739 CVE-2013-1741 CVE-2013-5605 CVE-2013-5606 CVE-2013-5607 ==================================================================== 1. Summary: Updated nss, nspr, and nss-util packages that fix multiple security issues are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64 3. Description: Network Security Services (NSS) is a set of libraries designed to support the cross-platform development of security-enabled client and server applications. Netscape Portable Runtime (NSPR) provides platform independence for non-GUI operating system facilities. A flaw was found in the way NSS handled invalid handshake packets.A remote attacker could use this flaw to cause a TLS/SSL client using NSS to crash or, possibly, execute arbitrary code with the privileges of the user running the application. (CVE-2013-5605) It was found that the fix for CVE-2013-1620 released via RHSA-2013:1135 introduced a regression causing NSS to read uninitialized data when a decryption failure occurred. A remote attacker could use this flaw to cause a TLS/SSL server using NSS to crash. (CVE-2013-1739) An integer overflow flaw was discovered in both NSS and NSPR's implementation of certification parsing on 64-bit systems. A remote attacker could use these flaws to cause an application using NSS or NSPR to crash. (CVE-2013-1741, CVE-2013-5607) It was discovered that NSS did not reject certificates with incompatible key usage constraints when validating them while the verifyLog feature was enabled. An application using the NSS certificate validation API could accept an invalid certificate. (CVE-2013-5606) Red Hat would like to thank the Mozilla project for reporting CVE-2013-1741, CVE-2013-5606, and CVE-2013-5607. Upstream acknowledges Tavis Ormandy as the original reporter of CVE-2013-1741, Camilo Viecco as the original reporter of CVE-2013-5606, and Pascal Cuoq, Kamil Dudka, and Wan-Teh Chang as the original reporters of CVE-2013-5607. All NSS, NSPR, and nss-util users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. After installing this update, applications using NSS, NSPR, or nss-util must be restarted for this update to take effect. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/site/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1012740 - CVE-2013-1739 nss: Avoid uninitialized data read in the event of a decryption failure 1030807 -CVE-2013-5605 nss: Null_Cipher() does not respect maxOutputLen (MFSA 2013-103) 1031457 - CVE-2013-5606 nss: CERT_VerifyCert returns SECSuccess (saying certificate is good) even for bad certificates (MFSA 2013-103) 1031458 - CVE-2013-1741 nss: Integer truncation in certificate parsing (MFSA 2013-103) 1031461 - CVE-2013-5607 nspr: Avoid unsigned integer wrapping in PL_ArenaAllocate (MFSA 2013-103) 6. Package List: Red Hat Enterprise Linux Desktop (v. 6): Source: i386: nspr-4.10.2-1.el6_5.i686.rpm nspr-debuginfo-4.10.2-1.el6_5.i686.rpm nss-3.15.3-2.el6_5.i686.rpm nss-debuginfo-3.15.3-2.el6_5.i686.rpm nss-sysinit-3.15.3-2.el6_5.i686.rpm nss-tools-3.15.3-2.el6_5.i686.rpm nss-util-3.15.3-1.el6_5.i686.rpm nss-util-debuginfo-3.15.3-1.el6_5.i686.rpm x86_64: nspr-4.10.2-1.el6_5.i686.rpm nspr-4.10.2-1.el6_5.x86_64.rpm nspr-debuginfo-4.10.2-1.el6_5.i686.rpm nspr-debuginfo-4.10.2-1.el6_5.x86_64.rpm nss-3.15.3-2.el6_5.i686.rpm nss-3.15.3-2.el6_5.x86_64.rpm nss-debuginfo-3.15.3-2.el6_5.i686.rpm nss-debuginfo-3.15.3-2.el6_5.x86_64.rpm nss-sysinit-3.15.3-2.el6_5.x86_64.rpm nss-tools-3.15.3-2.el6_5.x86_64.rpm nss-util-3.15.3-1.el6_5.i686.rpm nss-util-3.15.3-1.el6_5.x86_64.rpm nss-util-debuginfo-3.15.3-1.el6_5.i686.rpm nss-util-debuginfo-3.15.3-1.el6_5.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v.6): Source: i386: nspr-debuginfo-4.10.2-1.el6_5.i686.rpm nspr-devel-4.10.2-1.el6_5.i686.rpm nss-debuginfo-3.15.3-2.el6_5.i686.rpm nss-devel-3.15.3-2.el6_5.i686.rpm nss-pkcs11-devel-3.15.3-2.el6_5.i686.rpm nss-util-debuginfo-3.15.3-1.el6_5.i686.rpm nss-util-devel-3.15.3-1.el6_5.i686.rpm x86_64: nspr-debuginfo-4.10.2-1.el6_5.i686.rpm nspr-debuginfo-4.10.2-1.el6_5.x86_64.rpm nspr-devel-4.10.2-1.el6_5.i686.rpm nspr-devel-4.10.2-1.el6_5.x86_64.rpm nss-debuginfo-3.15.3-2.el6_5.i686.rpm nss-debuginfo-3.15.3-2.el6_5.x86_64.rpm nss-devel-3.15.3-2.el6_5.i686.rpm nss-devel-3.15.3-2.el6_5.x86_64.rpm nss-pkcs11-devel-3.15.3-2.el6_5.i686.rpm nss-pkcs11-devel-3.15.3-2.el6_5.x86_64.rpm nss-util-debuginfo-3.15.3-1.el6_5.i686.rpm nss-util-debuginfo-3.15.3-1.el6_5.x86_64.rpm nss-util-devel-3.15.3-1.el6_5.i686.rpm nss-util-devel-3.15.3-1.el6_5.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: x86_64: nspr-4.10.2-1.el6_5.i686.rpm nspr-4.10.2-1.el6_5.x86_64.rpm nspr-debuginfo-4.10.2-1.el6_5.i686.rpm nspr-debuginfo-4.10.2-1.el6_5.x86_64.rpm nss-3.15.3-2.el6_5.i686.rpm nss-3.15.3-2.el6_5.x86_64.rpm nss-debuginfo-3.15.3-2.el6_5.i686.rpm nss-debuginfo-3.15.3-2.el6_5.x86_64.rpm nss-sysinit-3.15.3-2.el6_5.x86_64.rpm nss-tools-3.15.3-2.el6_5.x86_64.rpm nss-util-3.15.3-1.el6_5.i686.rpm nss-util-3.15.3-1.el6_5.x86_64.rpm nss-util-debuginfo-3.15.3-1.el6_5.i686.rpm nss-util-debuginfo-3.15.3-1.el6_5.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): Source: x86_64: nspr-debuginfo-4.10.2-1.el6_5.i686.rpm nspr-debuginfo-4.10.2-1.el6_5.x86_64.rpm nspr-devel-4.10.2-1.el6_5.i686.rpm nspr-devel-4.10.2-1.el6_5.x86_64.rpm nss-debuginfo-3.15.3-2.el6_5.i686.rpm nss-debuginfo-3.15.3-2.el6_5.x86_64.rpm nss-devel-3.15.3-2.el6_5.i686.rpm nss-devel-3.15.3-2.el6_5.x86_64.rpm nss-pkcs11-devel-3.15.3-2.el6_5.i686.rpm nss-pkcs11-devel-3.15.3-2.el6_5.x86_64.rpm nss-util-debuginfo-3.15.3-1.el6_5.i686.rpm nss-util-debuginfo-3.15.3-1.el6_5.x86_64.rpm nss-util-devel-3.15.3-1.el6_5.i686.rpm nss-util-devel-3.15.3-1.el6_5.x86_64.rpm RedHat Enterprise Linux Server (v.6): Source: i386: nspr-4.10.2-1.el6_5.i686.rpm nspr-debuginfo-4.10.2-1.el6_5.i686.rpm nspr-devel-4.10.2-1.el6_5.i686.rpm nss-3.15.3-2.el6_5.i686.rpm nss-debuginfo-3.15.3-2.el6_5.i686.rpm nss-devel-3.15.3-2.el6_5.i686.rpm nss-sysinit-3.15.3-2.el6_5.i686.rpm nss-tools-3.15.3-2.el6_5.i686.rpm nss-util-3.15.3-1.el6_5.i686.rpm nss-util-debuginfo-3.15.3-1.el6_5.i686.rpm nss-util-devel-3.15.3-1.el6_5.i686.rpm ppc64: nspr-4.10.2-1.el6_5.ppc.rpm nspr-4.10.2-1.el6_5.ppc64.rpm nspr-debuginfo-4.10.2-1.el6_5.ppc.rpm nspr-debuginfo-4.10.2-1.el6_5.ppc64.rpm nspr-devel-4.10.2-1.el6_5.ppc.rpm nspr-devel-4.10.2-1.el6_5.ppc64.rpm nss-3.15.3-2.el6_5.ppc.rpm nss-3.15.3-2.el6_5.ppc64.rpm nss-debuginfo-3.15.3-2.el6_5.ppc.rpm nss-debuginfo-3.15.3-2.el6_5.ppc64.rpm nss-devel-3.15.3-2.el6_5.ppc.rpm nss-devel-3.15.3-2.el6_5.ppc64.rpm nss-sysinit-3.15.3-2.el6_5.ppc64.rpm nss-tools-3.15.3-2.el6_5.ppc64.rpm nss-util-3.15.3-1.el6_5.ppc.rpm nss-util-3.15.3-1.el6_5.ppc64.rpm nss-util-debuginfo-3.15.3-1.el6_5.ppc.rpm nss-util-debuginfo-3.15.3-1.el6_5.ppc64.rpm nss-util-devel-3.15.3-1.el6_5.ppc.rpm nss-util-devel-3.15.3-1.el6_5.ppc64.rpm s390x: nspr-4.10.2-1.el6_5.s390.rpm nspr-4.10.2-1.el6_5.s390x.rpm nspr-debuginfo-4.10.2-1.el6_5.s390.rpm nspr-debuginfo-4.10.2-1.el6_5.s390x.rpm nspr-devel-4.10.2-1.el6_5.s390.rpm nspr-devel-4.10.2-1.el6_5.s390x.rpm nss-3.15.3-2.el6_5.s390.rpm nss-3.15.3-2.el6_5.s390x.rpm nss-debuginfo-3.15.3-2.el6_5.s390.rpm nss-debuginfo-3.15.3-2.el6_5.s390x.rpm nss-devel-3.15.3-2.el6_5.s390.rpm nss-devel-3.15.3-2.el6_5.s390x.rpm nss-sysinit-3.15.3-2.el6_5.s390x.rpm nss-tools-3.15.3-2.el6_5.s390x.rpm nss-util-3.15.3-1.el6_5.s390.rpm nss-util-3.15.3-1.el6_5.s390x.rpm nss-util-debuginfo-3.15.3-1.el6_5.s390.rpm nss-util-debuginfo-3.15.3-1.el6_5.s390x.rpm nss-util-devel-3.15.3-1.el6_5.s390.rpm nss-util-devel-3.15.3-1.el6_5.s390x.rpm x86_64: nspr-4.10.2-1.el6_5.i686.rpm nspr-4.10.2-1.el6_5.x86_64.rpm nspr-debuginfo-4.10.2-1.el6_5.i686.rpm nspr-debuginfo-4.10.2-1.el6_5.x86_64.rpm nspr-devel-4.10.2-1.el6_5.i686.rpm nspr-devel-4.10.2-1.el6_5.x86_64.rpm nss-3.15.3-2.el6_5.i686.rpm nss-3.15.3-2.el6_5.x86_64.rpm nss-debuginfo-3.15.3-2.el6_5.i686.rpm nss-debuginfo-3.15.3-2.el6_5.x86_64.rpm nss-devel-3.15.3-2.el6_5.i686.rpm nss-devel-3.15.3-2.el6_5.x86_64.rpm nss-sysinit-3.15.3-2.el6_5.x86_64.rpm nss-tools-3.15.3-2.el6_5.x86_64.rpm nss-util-3.15.3-1.el6_5.i686.rpm nss-util-3.15.3-1.el6_5.x86_64.rpm nss-util-debuginfo-3.15.3-1.el6_5.i686.rpm nss-util-debuginfo-3.15.3-1.el6_5.x86_64.rpm nss-util-devel-3.15.3-1.el6_5.i686.rpm nss-util-devel-3.15.3-1.el6_5.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 6): Source: i386: nss-debuginfo-3.15.3-2.el6_5.i686.rpm nss-pkcs11-devel-3.15.3-2.el6_5.i686.rpm ppc64: nss-debuginfo-3.15.3-2.el6_5.ppc.rpm nss-debuginfo-3.15.3-2.el6_5.ppc64.rpm nss-pkcs11-devel-3.15.3-2.el6_5.ppc.rpm nss-pkcs11-devel-3.15.3-2.el6_5.ppc64.rpm s390x: nss-debuginfo-3.15.3-2.el6_5.s390.rpm nss-debuginfo-3.15.3-2.el6_5.s390x.rpm nss-pkcs11-devel-3.15.3-2.el6_5.s390.rpm nss-pkcs11-devel-3.15.3-2.el6_5.s390x.rpm x86_64: nss-debuginfo-3.15.3-2.el6_5.i686.rpm nss-debuginfo-3.15.3-2.el6_5.x86_64.rpm nss-pkcs11-devel-3.15.3-2.el6_5.i686.rpm nss-pkcs11-devel-3.15.3-2.el6_5.x86_64.rpm Red Hat Enterprise Linux Workstation (v.6): Source: i386: nspr-4.10.2-1.el6_5.i686.rpm nspr-debuginfo-4.10.2-1.el6_5.i686.rpm nspr-devel-4.10.2-1.el6_5.i686.rpm nss-3.15.3-2.el6_5.i686.rpm nss-debuginfo-3.15.3-2.el6_5.i686.rpm nss-devel-3.15.3-2.el6_5.i686.rpm nss-sysinit-3.15.3-2.el6_5.i686.rpm nss-tools-3.15.3-2.el6_5.i686.rpm nss-util-3.15.3-1.el6_5.i686.rpm nss-util-debuginfo-3.15.3-1.el6_5.i686.rpm nss-util-devel-3.15.3-1.el6_5.i686.rpm x86_64: nspr-4.10.2-1.el6_5.i686.rpm nspr-4.10.2-1.el6_5.x86_64.rpm nspr-debuginfo-4.10.2-1.el6_5.i686.rpm nspr-debuginfo-4.10.2-1.el6_5.x86_64.rpm nspr-devel-4.10.2-1.el6_5.i686.rpm nspr-devel-4.10.2-1.el6_5.x86_64.rpm nss-3.15.3-2.el6_5.i686.rpm nss-3.15.3-2.el6_5.x86_64.rpm nss-debuginfo-3.15.3-2.el6_5.i686.rpm nss-debuginfo-3.15.3-2.el6_5.x86_64.rpm nss-devel-3.15.3-2.el6_5.i686.rpm nss-devel-3.15.3-2.el6_5.x86_64.rpm nss-sysinit-3.15.3-2.el6_5.x86_64.rpm nss-tools-3.15.3-2.el6_5.x86_64.rpm nss-util-3.15.3-1.el6_5.i686.rpm nss-util-3.15.3-1.el6_5.x86_64.rpm nss-util-debuginfo-3.15.3-1.el6_5.i686.rpm nss-util-debuginfo-3.15.3-1.el6_5.x86_64.rpm nss-util-devel-3.15.3-1.el6_5.i686.rpm nss-util-devel-3.15.3-1.el6_5.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): Source: i386: nss-debuginfo-3.15.3-2.el6_5.i686.rpm nss-pkcs11-devel-3.15.3-2.el6_5.i686.rpm x86_64: nss-debuginfo-3.15.3-2.el6_5.i686.rpm nss-debuginfo-3.15.3-2.el6_5.x86_64.rpm nss-pkcs11-devel-3.15.3-2.el6_5.i686.rpm nss-pkcs11-devel-3.15.3-2.el6_5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7.References: https://access.redhat.com/security/cve/CVE-2013-1739 https://access.redhat.com/security/cve/CVE-2013-1741 https://access.redhat.com/security/cve/CVE-2013-5605 https://access.redhat.com/security/cve/CVE-2013-5606 https://access.redhat.com/security/cve/CVE-2013-5607 https://access.redhat.com/security/updates/classification#important https://www.mozilla.org/en-US/security/advisories/mfsa2013-103/ 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2013 Red Hat, Inc. . Red Hat has issued important advisories regarding crucial updates for nss and nspr on the RHEL 6 platform to fix vulnerabilities and boost security.. NSS Security Update, NSPR Issues, RHEL 6 Fixes. . Severity: Important. LinuxSecurity.com Team
Important: nss and nspr security, bug fix, and enhancement update. Date: Mon, 9 Dec 2013 09:59:16 -0600 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Attention SL 5 MySQL users, mysql is changing! MIME-Version: 1.0 Attention SL 5 MySQL users: Upstream will not issue any more security advisories for the MySQL 5.0 packages (mysql-5.0.* and related packages). In order to ensure your systems are fully up to date with security errata, you must migrate to the newly provided MySQL 5.5 packages. Future security advisories will be provided only for MySQL 5.5. The only trusted way to upgrade from MySQL 5.0 to MySQL 5.5 is by using MySQL 5.1 as an intermediate step. This is why the mysql51* Software Collection packages are provided. Note that the MySQL 5.1 packages are not supported and are provided only for the purposes of migrating to MySQL 5.5. You should not use the mysql51* packages on any of your production systems. Because the mysql51 and mysql55 Software Collections do not conflict with each other, or any mysql packages, users can install mysql51 and mysql55 Software Collections together with mysql packages. We have placed the relevant mysql packages within the Scientific Linux 5 security tree to facilitate this upgrade in advance of any actual security errata. Giving you the time to test this migration should result in you being better prepared for a time when you must perform it to maintain your system security. Specific instructions for this migration are provided by upstream at: https://docs.redhat.com/en/documentation/Red_Hat_Enterprise_Linux/5/html/Deployment_Guide/ch-Migrating_from_MySQL_5.0_to_MySQL_5.5.html -- Pat Riehecky Scientific Linux developer Date: Mon, 9 Dec 2013 16:00:12 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Important: nss and nspr on SL5.x i386/x86_64 MIME-Version: 1.0 Synopsis: Important: nss and nspr security, bug fix, andenhancement update Advisory ID: SLSA-2013:1791-1 Issue Date: 2013-12-05 CVE Numbers: CVE-2013-1739 CVE-2013-5605 CVE-2013-5606 CVE-2013-1741 CVE-2013-5607 -- A flaw was found in the way NSS handled invalid handshake packets. A remote attacker could use this flaw to cause a TLS/SSL client using NSS to crash or, possibly, execute arbitrary code with the privileges of the user running the application. (CVE-2013-5605) It was found that the fix for CVE-2013-1620 released via SLSA-2013:1135 introduced a regression causing NSS to read uninitialized data when a decryption failure occurred. A remote attacker could use this flaw to cause a TLS/SSL server using NSS to crash. (CVE-2013-1739) An integer overflow flaw was discovered in both NSS and NSPR's implementation of certification parsing on 64-bit systems. A remote attacker could use these flaws to cause an application using NSS or NSPR to crash. (CVE-2013-1741, CVE-2013-5607) It was discovered that NSS did not reject certificates with incompatible key usage constraints when validating them while the verifyLog feature was enabled. An application using the NSS certificate validation API could accept an invalid certificate. (CVE-2013-5606) In addition, the nss package has been upgraded to upstream version 3.15.3, and the nspr package has been upgraded to upstream version 4.10.2. These updates provide a number of bug fixes and enhancements over the previous versions. This update also fixes the following bug: * The SLBA-2013:1318 update introduced a regression that prevented the use of certificates that have an MD5 signature. This update fixes this regression and certificates that have an MD5 signature are once again supported. To prevent the use of certificates that have an MD5 signature, set the "NSS_HASH_ALG_SUPPORT" environment variable to "-MD5". After installing this update, applications using NSS or NSPR must be restarted for this update to take effect. -- SL5 x86_64 nspr-4.10.2-2.el5_10.i386.rpm nspr-4.10.2-2.el5_10.x86_64.rpm nspr-debuginfo-4.10.2-2.el5_10.i386.rpm nspr-debuginfo-4.10.2-2.el5_10.x86_64.rpm nss-3.15.3-3.el5_10.i386.rpm nss-3.15.3-3.el5_10.x86_64.rpm nss-debuginfo-3.15.3-3.el5_10.i386.rpm nss-debuginfo-3.15.3-3.el5_10.x86_64.rpm nss-tools-3.15.3-3.el5_10.x86_64.rpm nspr-devel-4.10.2-2.el5_10.i386.rpm nspr-devel-4.10.2-2.el5_10.x86_64.rpm nss-devel-3.15.3-3.el5_10.i386.rpm nss-devel-3.15.3-3.el5_10.x86_64.rpm nss-pkcs11-devel-3.15.3-3.el5_10.i386.rpm nss-pkcs11-devel-3.15.3-3.el5_10.x86_64.rpm i386 nspr-4.10.2-2.el5_10.i386.rpm nspr-debuginfo-4.10.2-2.el5_10.i386.rpm nss-3.15.3-3.el5_10.i386.rpm nss-debuginfo-3.15.3-3.el5_10.i386.rpm nss-tools-3.15.3-3.el5_10.i386.rpm nspr-devel-4.10.2-2.el5_10.i386.rpm nss-devel-3.15.3-3.el5_10.i386.rpm nss-pkcs11-devel-3.15.3-3.el5_10.i386.rpm - Scientific Linux Development Team . Crucial NSS and NSPR security patch for Scientific Linux SL5.x addressing several vulnerabilities and corrective measures.. nss Update,nsp Update,Important Security Warning,Scientific Linux. . Severity: Important. LinuxSecurity.com Team
Updated nss and nspr packages that fix multiple security issues, several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: nss and nspr security, bug fix, and enhancement update Advisory ID: RHSA-2013:1791-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2013:1791.html Issue date: 2013-12-05 CVE Names: CVE-2013-1739 CVE-2013-1741 CVE-2013-5605 CVE-2013-5606 CVE-2013-5607 ==================================================================== 1. Summary: Updated nss and nspr packages that fix multiple security issues, several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 3. Description: Network Security Services (NSS) is a set of libraries designed to support the cross-platform development of security-enabled client and server applications. Netscape Portable Runtime (NSPR) provides platform independence for non-GUI operating system facilities. A flaw was found in the way NSS handled invalid handshake packets. A remote attacker could use this flaw to cause a TLS/SSL client using NSS to crash or, possibly, execute arbitrary code with the privileges of the user running the application.(CVE-2013-5605) It was found that the fix for CVE-2013-1620 released via RHSA-2013:1135 introduced a regression causing NSS to read uninitialized data when a decryption failure occurred. A remote attacker could use this flaw to cause a TLS/SSL server using NSS to crash. (CVE-2013-1739) An integer overflow flaw was discovered in both NSS and NSPR's implementation of certification parsing on 64-bit systems. A remote attacker could use these flaws to cause an application using NSS or NSPR to crash. (CVE-2013-1741, CVE-2013-5607) It was discovered that NSS did not reject certificates with incompatible key usage constraints when validating them while the verifyLog feature was enabled. An application using the NSS certificate validation API could accept an invalid certificate. (CVE-2013-5606) Red Hat would like to thank the Mozilla project for reporting CVE-2013-1741, CVE-2013-5606, and CVE-2013-5607. Upstream acknowledges Tavis Ormandy as the original reporter of CVE-2013-1741, Camilo Viecco as the original reporter of CVE-2013-5606, and Pascal Cuoq, Kamil Dudka, and Wan-Teh Chang as the original reporters of CVE-2013-5607. In addition, the nss package has been upgraded to upstream version 3.15.3, and the nspr package has been upgraded to upstream version 4.10.2. These updates provide a number of bug fixes and enhancements over the previous versions. (BZ#1033478, BZ#1020520) This update also fixes the following bug: * The RHBA-2013:1318 update introduced a regression that prevented the use of certificates that have an MD5 signature. This update fixes this regression and certificates that have an MD5 signature are once again supported. To prevent the use of certificates that have an MD5 signature, set the "NSS_HASH_ALG_SUPPORT" environment variable to "-MD5". (BZ#1033499) Users of NSS and NSPR are advised to upgrade to these updated packages, which fix these issues and add these enhancements. After installing this update, applications using NSS or NSPR must be restarted for this update to take effect. 4.Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/site/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1012740 - CVE-2013-1739 nss: Avoid uninitialized data read in the event of a decryption failure 1030807 - CVE-2013-5605 nss: Null_Cipher() does not respect maxOutputLen (MFSA 2013-103) 1031457 - CVE-2013-5606 nss: CERT_VerifyCert returns SECSuccess (saying certificate is good) even for bad certificates (MFSA 2013-103) 1031458 - CVE-2013-1741 nss: Integer truncation in certificate parsing (MFSA 2013-103) 1031461 - CVE-2013-5607 nspr: Avoid unsigned integer wrapping in PL_ArenaAllocate (MFSA 2013-103) 6. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: nspr-4.10.2-2.el5_10.i386.rpm nspr-debuginfo-4.10.2-2.el5_10.i386.rpm nss-3.15.3-3.el5_10.i386.rpm nss-debuginfo-3.15.3-3.el5_10.i386.rpm nss-tools-3.15.3-3.el5_10.i386.rpm x86_64: nspr-4.10.2-2.el5_10.i386.rpm nspr-4.10.2-2.el5_10.x86_64.rpm nspr-debuginfo-4.10.2-2.el5_10.i386.rpm nspr-debuginfo-4.10.2-2.el5_10.x86_64.rpm nss-3.15.3-3.el5_10.i386.rpm nss-3.15.3-3.el5_10.x86_64.rpm nss-debuginfo-3.15.3-3.el5_10.i386.rpm nss-debuginfo-3.15.3-3.el5_10.x86_64.rpm nss-tools-3.15.3-3.el5_10.x86_64.rpm RHEL Desktop Workstation (v. 5client): Source: i386: nspr-debuginfo-4.10.2-2.el5_10.i386.rpm nspr-devel-4.10.2-2.el5_10.i386.rpm nss-debuginfo-3.15.3-3.el5_10.i386.rpm nss-devel-3.15.3-3.el5_10.i386.rpm nss-pkcs11-devel-3.15.3-3.el5_10.i386.rpm x86_64: nspr-debuginfo-4.10.2-2.el5_10.i386.rpm nspr-debuginfo-4.10.2-2.el5_10.x86_64.rpm nspr-devel-4.10.2-2.el5_10.i386.rpm nspr-devel-4.10.2-2.el5_10.x86_64.rpm nss-debuginfo-3.15.3-3.el5_10.i386.rpm nss-debuginfo-3.15.3-3.el5_10.x86_64.rpm nss-devel-3.15.3-3.el5_10.i386.rpm nss-devel-3.15.3-3.el5_10.x86_64.rpm nss-pkcs11-devel-3.15.3-3.el5_10.i386.rpm nss-pkcs11-devel-3.15.3-3.el5_10.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: nspr-4.10.2-2.el5_10.i386.rpm nspr-debuginfo-4.10.2-2.el5_10.i386.rpm nspr-devel-4.10.2-2.el5_10.i386.rpm nss-3.15.3-3.el5_10.i386.rpm nss-debuginfo-3.15.3-3.el5_10.i386.rpm nss-devel-3.15.3-3.el5_10.i386.rpm nss-pkcs11-devel-3.15.3-3.el5_10.i386.rpm nss-tools-3.15.3-3.el5_10.i386.rpm ia64: nspr-4.10.2-2.el5_10.i386.rpm nspr-4.10.2-2.el5_10.ia64.rpm nspr-debuginfo-4.10.2-2.el5_10.i386.rpm nspr-debuginfo-4.10.2-2.el5_10.ia64.rpm nspr-devel-4.10.2-2.el5_10.ia64.rpm nss-3.15.3-3.el5_10.i386.rpm nss-3.15.3-3.el5_10.ia64.rpm nss-debuginfo-3.15.3-3.el5_10.i386.rpm nss-debuginfo-3.15.3-3.el5_10.ia64.rpm nss-devel-3.15.3-3.el5_10.ia64.rpm nss-pkcs11-devel-3.15.3-3.el5_10.ia64.rpm nss-tools-3.15.3-3.el5_10.ia64.rpm ppc: nspr-4.10.2-2.el5_10.ppc.rpm nspr-4.10.2-2.el5_10.ppc64.rpm nspr-debuginfo-4.10.2-2.el5_10.ppc.rpm nspr-debuginfo-4.10.2-2.el5_10.ppc64.rpm nspr-devel-4.10.2-2.el5_10.ppc.rpm nspr-devel-4.10.2-2.el5_10.ppc64.rpm nss-3.15.3-3.el5_10.ppc.rpm nss-3.15.3-3.el5_10.ppc64.rpm nss-debuginfo-3.15.3-3.el5_10.ppc.rpm nss-debuginfo-3.15.3-3.el5_10.ppc64.rpm nss-devel-3.15.3-3.el5_10.ppc.rpm nss-devel-3.15.3-3.el5_10.ppc64.rpm nss-pkcs11-devel-3.15.3-3.el5_10.ppc.rpm nss-pkcs11-devel-3.15.3-3.el5_10.ppc64.rpm nss-tools-3.15.3-3.el5_10.ppc.rpm s390x: nspr-4.10.2-2.el5_10.s390.rpm nspr-4.10.2-2.el5_10.s390x.rpm nspr-debuginfo-4.10.2-2.el5_10.s390.rpm nspr-debuginfo-4.10.2-2.el5_10.s390x.rpm nspr-devel-4.10.2-2.el5_10.s390.rpm nspr-devel-4.10.2-2.el5_10.s390x.rpm nss-3.15.3-3.el5_10.s390.rpm nss-3.15.3-3.el5_10.s390x.rpm nss-debuginfo-3.15.3-3.el5_10.s390.rpm nss-debuginfo-3.15.3-3.el5_10.s390x.rpm nss-devel-3.15.3-3.el5_10.s390.rpm nss-devel-3.15.3-3.el5_10.s390x.rpm nss-pkcs11-devel-3.15.3-3.el5_10.s390.rpm nss-pkcs11-devel-3.15.3-3.el5_10.s390x.rpm nss-tools-3.15.3-3.el5_10.s390x.rpm x86_64: nspr-4.10.2-2.el5_10.i386.rpm nspr-4.10.2-2.el5_10.x86_64.rpm nspr-debuginfo-4.10.2-2.el5_10.i386.rpm nspr-debuginfo-4.10.2-2.el5_10.x86_64.rpm nspr-devel-4.10.2-2.el5_10.i386.rpm nspr-devel-4.10.2-2.el5_10.x86_64.rpm nss-3.15.3-3.el5_10.i386.rpm nss-3.15.3-3.el5_10.x86_64.rpm nss-debuginfo-3.15.3-3.el5_10.i386.rpm nss-debuginfo-3.15.3-3.el5_10.x86_64.rpm nss-devel-3.15.3-3.el5_10.i386.rpm nss-devel-3.15.3-3.el5_10.x86_64.rpm nss-pkcs11-devel-3.15.3-3.el5_10.i386.rpm nss-pkcs11-devel-3.15.3-3.el5_10.x86_64.rpm nss-tools-3.15.3-3.el5_10.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://access.redhat.com/security/cve/CVE-2013-1739 https://access.redhat.com/security/cve/CVE-2013-1741 https://access.redhat.com/security/cve/CVE-2013-5605 https://access.redhat.com/security/cve/CVE-2013-5606 https://access.redhat.com/security/cve/CVE-2013-5607 https://access.redhat.com/security/updates/classification/#important https://www.mozilla.org/en-US/security/advisories/mfsa2013-103/ 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2013 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFSoLz+XlSAg2UNWIIRAjaOAKC1e50CeEPRmLfk0LmHjX/Esn4I4ACglhuw 9jyKZmZ6Wq61vCFsITja2vU=46P5 -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
NSPR update to work with the new NSS.. =========================================================================Ubuntu Security Notice USN-1763-2 March 14, 2013 nspr update ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.10 - Ubuntu 12.04 LTS - Ubuntu 11.10 - Ubuntu 10.04 LTS Summary: NSPR update to work with the new NSS. Software Description: - nspr: NetScape Portable Runtime Library Details: USN-1763-1 fixed a vulnerability in NSS. This update provides the NSPR needed to use the new NSS. Original advisory details: Nadhem Alfardan and Kenny Paterson discovered that the TLS protocol as used in NSS was vulnerable to a timing side-channel attack known as the "Lucky Thirteen" issue. A remote attacker could use this issue to perform plaintext-recovery attacks via analysis of timing data. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.10: libnspr4 4.9.5-0ubuntu0.12.10.1 Ubuntu 12.04 LTS: libnspr4 4.9.5-0ubuntu0.12.04.1 Ubuntu 11.10: libnspr4 4.9.5-0ubuntu0.11.10.1 Ubuntu 10.04 LTS: libnspr4-0d 4.9.5-0ubuntu0.10.04.1 After a standard system update you need to restart any applications that use NSPR, such as Evolution and Chromium, to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1763-2 https://ubuntu.com/security/notices/USN-1763-1 https://bugs.launchpad.net/ubuntu/+source/nspr/+bug/1155295 Package Information: https://launchpad.net/ubuntu/+source/nspr/4.9.5-0ubuntu0.12.10.1 https://launchpad.net/ubuntu/+source/nspr/4.9.5-0ubuntu0.12.04.1 https://launchpad.net/ubuntu/+source/nspr/4.9.5-0ubuntu0.11.10.1 https://launchpad.net/ubuntu/+source/nspr/4.9.5-0ubuntu0.10.04.1 . Critical NSPR patch released forUbuntu to address vulnerabilities. Key for maintaining system integrity and ensuring security standards are upheld.. NSPR Update, Ubuntu Security, Timing Attack Fix. . Severity: Critical. LinuxSecurity.com Team
Important: nss and nspr security, bug fix, and . Date: Fri, 1 Feb 2013 09:47:43 -0600 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: Security ERRATA Important: nss and nspr on SL5.x i386/x86_64 Synopsis: Important: nss and nspr security, bug fix, and enhancement update Issue Date: 2013-01-31 CVE Numbers: None -- It was found that a Certificate Authority (CA) mis-issued two intermediate certificates to customers. These certificates could be used to launch man-in-the-middle attacks. This update renders those certificates as untrusted. This covers all uses of the certificates, including SSL, S/MIME, and code signing. In addition, the nss package has been upgraded to upstream version 3.13.6, and the nspr package has been upgraded to upstream version 4.9.2. These updates provide a number of bug fixes and enhancements over the previous versions. After installing the update, applications using NSS and NSPR must be restarted for the changes to take effect. -- SL5 x86_64 nspr-4.9.2-2.el5_9.i386.rpm nspr-4.9.2-2.el5_9.x86_64.rpm nspr-debuginfo-4.9.2-2.el5_9.i386.rpm nspr-debuginfo-4.9.2-2.el5_9.x86_64.rpm nss-3.13.6-3.el5_9.i386.rpm nss-3.13.6-3.el5_9.x86_64.rpm nss-debuginfo-3.13.6-3.el5_9.i386.rpm nss-debuginfo-3.13.6-3.el5_9.x86_64.rpm nss-tools-3.13.6-3.el5_9.x86_64.rpm nspr-devel-4.9.2-2.el5_9.i386.rpm nspr-devel-4.9.2-2.el5_9.x86_64.rpm nss-devel-3.13.6-3.el5_9.i386.rpm nss-devel-3.13.6-3.el5_9.x86_64.rpm nss-pkcs11-devel-3.13.6-3.el5_9.i386.rpm nss-pkcs11-devel-3.13.6-3.el5_9.x86_64.rpm i386 nspr-4.9.2-2.el5_9.i386.rpm nspr-debuginfo-4.9.2-2.el5_9.i386.rpm nss-3.13.6-3.el5_9.i386.rpm nss-debuginfo-3.13.6-3.el5_9.i386.rpm nss-tools-3.13.6-3.el5_9.i386.rpm nspr-devel-4.9.2-2.el5_9.i386.rpm nss-devel-3.13.6-3.el5_9.i386.rpm nss-pkcs11-devel-3.13.6-3.el5_9.i386.rpm - Scientific Linux Development Team . TSS and TSPR patches address severe vulnerabilities impacting Research Linux 6.x, boosting overallsecurity.. NSS Update, NSPR Update, Security Fix, Scientific Linux Security, Certificate Vulnerabilities. . Severity: Important. LinuxSecurity.com Team
Updated nss and nspr packages that fix one security issue, various bugs, and add enhancements are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having important security impact.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: nss and nspr security, bug fix, and enhancement update Advisory ID: RHSA-2013:0214-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2013:0214.html Issue date: 2013-01-31 ==================================================================== 1. Summary: Updated nss and nspr packages that fix one security issue, various bugs, and add enhancements are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having important security impact. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 3. Description: Network Security Services (NSS) is a set of libraries designed to support the cross-platform development of security-enabled client and server applications. Netscape Portable Runtime (NSPR) provides platform independence for non-GUI operating system facilities. It was found that a Certificate Authority (CA) mis-issued two intermediate certificates to customers. These certificates could be used to launch man-in-the-middle attacks. This update renders those certificates as untrusted. This covers all uses of the certificates, including SSL, S/MIME, and code signing. (BZ#890605) In addition, the nss package has been upgraded to upstream version 3.13.6, and the nspr package has been upgraded to upstream version 4.9.2. These updates provide a number of bug fixes and enhancements over theprevious versions. (BZ#893371, BZ#893372) All NSS and NSPR users should upgrade to these updated packages, which correct these issues and add these enhancements. After installing the update, applications using NSS and NSPR must be restarted for the changes to take effect. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/knowledge/articles/11258 5. Bugs fixed (http://bugzilla.redhat.com/): 890605 - nss: Dis-trust TURKTRUST mis-issued *.google.com certificate 893371 - [RFE] [RHEL5] Rebase to NSS > = 3.13.6 893372 - [RFE] Rebase nspr to 4.9.2 due to Firefox 17 ESR 6. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: nspr-4.9.2-2.el5_9.i386.rpm nspr-debuginfo-4.9.2-2.el5_9.i386.rpm nss-3.13.6-3.el5_9.i386.rpm nss-debuginfo-3.13.6-3.el5_9.i386.rpm nss-tools-3.13.6-3.el5_9.i386.rpm x86_64: nspr-4.9.2-2.el5_9.i386.rpm nspr-4.9.2-2.el5_9.x86_64.rpm nspr-debuginfo-4.9.2-2.el5_9.i386.rpm nspr-debuginfo-4.9.2-2.el5_9.x86_64.rpm nss-3.13.6-3.el5_9.i386.rpm nss-3.13.6-3.el5_9.x86_64.rpm nss-debuginfo-3.13.6-3.el5_9.i386.rpm nss-debuginfo-3.13.6-3.el5_9.x86_64.rpm nss-tools-3.13.6-3.el5_9.x86_64.rpm RHEL Desktop Workstation (v. 5 client): Source: i386: nspr-debuginfo-4.9.2-2.el5_9.i386.rpm nspr-devel-4.9.2-2.el5_9.i386.rpm nss-debuginfo-3.13.6-3.el5_9.i386.rpm nss-devel-3.13.6-3.el5_9.i386.rpm nss-pkcs11-devel-3.13.6-3.el5_9.i386.rpm x86_64: nspr-debuginfo-4.9.2-2.el5_9.i386.rpm nspr-debuginfo-4.9.2-2.el5_9.x86_64.rpm nspr-devel-4.9.2-2.el5_9.i386.rpm nspr-devel-4.9.2-2.el5_9.x86_64.rpm nss-debuginfo-3.13.6-3.el5_9.i386.rpm nss-debuginfo-3.13.6-3.el5_9.x86_64.rpm nss-devel-3.13.6-3.el5_9.i386.rpm nss-devel-3.13.6-3.el5_9.x86_64.rpm nss-pkcs11-devel-3.13.6-3.el5_9.i386.rpm nss-pkcs11-devel-3.13.6-3.el5_9.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: nspr-4.9.2-2.el5_9.i386.rpm nspr-debuginfo-4.9.2-2.el5_9.i386.rpm nspr-devel-4.9.2-2.el5_9.i386.rpm nss-3.13.6-3.el5_9.i386.rpm nss-debuginfo-3.13.6-3.el5_9.i386.rpm nss-devel-3.13.6-3.el5_9.i386.rpm nss-pkcs11-devel-3.13.6-3.el5_9.i386.rpm nss-tools-3.13.6-3.el5_9.i386.rpm ia64: nspr-4.9.2-2.el5_9.i386.rpm nspr-4.9.2-2.el5_9.ia64.rpm nspr-debuginfo-4.9.2-2.el5_9.i386.rpm nspr-debuginfo-4.9.2-2.el5_9.ia64.rpm nspr-devel-4.9.2-2.el5_9.ia64.rpm nss-3.13.6-3.el5_9.i386.rpm nss-3.13.6-3.el5_9.ia64.rpm nss-debuginfo-3.13.6-3.el5_9.i386.rpm nss-debuginfo-3.13.6-3.el5_9.ia64.rpm nss-devel-3.13.6-3.el5_9.ia64.rpm nss-pkcs11-devel-3.13.6-3.el5_9.ia64.rpm nss-tools-3.13.6-3.el5_9.ia64.rpm ppc: nspr-4.9.2-2.el5_9.ppc.rpm nspr-4.9.2-2.el5_9.ppc64.rpm nspr-debuginfo-4.9.2-2.el5_9.ppc.rpm nspr-debuginfo-4.9.2-2.el5_9.ppc64.rpm nspr-devel-4.9.2-2.el5_9.ppc.rpm nspr-devel-4.9.2-2.el5_9.ppc64.rpm nss-3.13.6-3.el5_9.ppc.rpm nss-3.13.6-3.el5_9.ppc64.rpm nss-debuginfo-3.13.6-3.el5_9.ppc.rpm nss-debuginfo-3.13.6-3.el5_9.ppc64.rpm nss-devel-3.13.6-3.el5_9.ppc.rpm nss-devel-3.13.6-3.el5_9.ppc64.rpm nss-pkcs11-devel-3.13.6-3.el5_9.ppc.rpm nss-pkcs11-devel-3.13.6-3.el5_9.ppc64.rpm nss-tools-3.13.6-3.el5_9.ppc.rpm s390x: nspr-4.9.2-2.el5_9.s390.rpm nspr-4.9.2-2.el5_9.s390x.rpm nspr-debuginfo-4.9.2-2.el5_9.s390.rpm nspr-debuginfo-4.9.2-2.el5_9.s390x.rpm nspr-devel-4.9.2-2.el5_9.s390.rpm nspr-devel-4.9.2-2.el5_9.s390x.rpm nss-3.13.6-3.el5_9.s390.rpm nss-3.13.6-3.el5_9.s390x.rpm nss-debuginfo-3.13.6-3.el5_9.s390.rpm nss-debuginfo-3.13.6-3.el5_9.s390x.rpm nss-devel-3.13.6-3.el5_9.s390.rpm nss-devel-3.13.6-3.el5_9.s390x.rpm nss-pkcs11-devel-3.13.6-3.el5_9.s390.rpm nss-pkcs11-devel-3.13.6-3.el5_9.s390x.rpm nss-tools-3.13.6-3.el5_9.s390x.rpm x86_64: nspr-4.9.2-2.el5_9.i386.rpm nspr-4.9.2-2.el5_9.x86_64.rpm nspr-debuginfo-4.9.2-2.el5_9.i386.rpm nspr-debuginfo-4.9.2-2.el5_9.x86_64.rpm nspr-devel-4.9.2-2.el5_9.i386.rpm nspr-devel-4.9.2-2.el5_9.x86_64.rpm nss-3.13.6-3.el5_9.i386.rpm nss-3.13.6-3.el5_9.x86_64.rpm nss-debuginfo-3.13.6-3.el5_9.i386.rpm nss-debuginfo-3.13.6-3.el5_9.x86_64.rpm nss-devel-3.13.6-3.el5_9.i386.rpm nss-devel-3.13.6-3.el5_9.x86_64.rpm nss-pkcs11-devel-3.13.6-3.el5_9.i386.rpm nss-pkcs11-devel-3.13.6-3.el5_9.x86_64.rpm nss-tools-3.13.6-3.el5_9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://access.redhat.com/security/updates/classification/#important https://www.mozilla.org/en-US/security/advisories/mfsa2013-20/ 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2013 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFRCufHXlSAg2UNWIIRAmwuAJ9JeZAVTboSNRYKGvidXCBgrfz6FQCfYuMv 7hkvClvoRuBJCMIGPEKMMVg=Nuzb -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Important: nss and nspr security update. Date: Tue, 13 Sep 2011 11:45:24 -0500 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: Security ERRATA Important: nss and nspr on SL4.x, SL5.x, SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Important: nss and nspr security update Issue Date: 2011-09-12 Network Security Services (NSS) is a set of libraries designed to support the cross-platform development of security-enabled client and server applications. Netscape Portable Runtime (NSPR) provides platform independence for non-GUI operating system facilities. It was found that a Certificate Authority (CA) issued fraudulent HTTPS certificates. This update renders any HTTPS certificates signed by that CA as untrusted. This covers all uses of the certificates, including SSL, S/MIME, and code signing. Note: This fix only applies to applications using the NSS Builtin Object Token. It does not render the certificates untrusted for applications that use the NSS library, but do not use the NSS Builtin Object Token. These updated packages upgrade NSS to version 3.12.10 on Scientific Linux 4 and 5. As well, they upgrade NSPR to version 4.8.8 on Scientific Linux 4 and 5, as required by the NSS update. The packages for Scientific Linux 6 include a backported patch. All NSS and NSPR users should upgrade to these updated packages, which correct this issue. After installing the update, applications using NSS and NSPR must be restarted for the changes to take effect. SL4: i386 nspr-4.8.8-1.el4.i386.rpm nss-devel-3.12.10-4.el4.i386.rpm nss-3.12.10-4.el4.i386.rpm nss-debuginfo-3.12.10-4.el4.i386.rpm nspr-devel-4.8.8-1.el4.i386.rpm nspr-debuginfo-4.8.8-1.el4.i386.rpm nss-tools-3.12.10-4.el4.i386.rpm x86_64 nss-devel-3.12.10-4.el4.x86_64.rpm nspr-4.8.8-1.el4.x86_64.rpm nspr-4.8.8-1.el4.i386.rpm nspr-debuginfo-4.8.8-1.el4.i386.rpm nspr-debuginfo-4.8.8-1.el4.x86_64.rpm nss-debuginfo-3.12.10-4.el4.x86_64.rpm nspr-devel-4.8.8-1.el4.x86_64.rpm nss-debuginfo-3.12.10-4.el4.i386.rpm nss-3.12.10-4.el4.i386.rpm nss-3.12.10-4.el4.x86_64.rpm nss-tools-3.12.10-4.el4.x86_64.rpm SL5: i386 nspr-devel-4.8.8-1.el5_7.i386.rpm nspr-debuginfo-4.8.8-1.el5_7.i386.rpm nss-debuginfo-3.12.10-4.el5_7.i386.rpm nss-devel-3.12.10-4.el5_7.i386.rpm nspr-4.8.8-1.el5_7.i386.rpm nss-tools-3.12.10-4.el5_7.i386.rpm nss-pkcs11-devel-3.12.10-4.el5_7.i386.rpm nss-3.12.10-4.el5_7.i386.rpm x86_64 nss-3.12.10-4.el5_7.x86_64.rpm nss-debuginfo-3.12.10-4.el5_7.i386.rpm nss-tools-3.12.10-4.el5_7.x86_64.rpm nss-devel-3.12.10-4.el5_7.x86_64.rpm nss-debuginfo-3.12.10-4.el5_7.x86_64.rpm nss-pkcs11-devel-3.12.10-4.el5_7.i386.rpm nss-pkcs11-devel-3.12.10-4.el5_7.x86_64.rpm nss-devel-3.12.10-4.el5_7.i386.rpm nss-3.12.10-4.el5_7.i386.rpm nspr-devel-4.8.8-1.el5_7.x86_64.rpm nspr-4.8.8-1.el5_7.i386.rpm nspr-4.8.8-1.el5_7.x86_64.rpm nspr-debuginfo-4.8.8-1.el5_7.i386.rpm nspr-debuginfo-4.8.8-1.el5_7.x86_64.rpm nspr-devel-4.8.8-1.el5_7.i386.rpm SL6: i386 nss-debuginfo-3.12.9-12.el6_1.i686.rpm nss-3.12.9-12.el6_1.i686.rpm nss-devel-3.12.9-12.el6_1.i686.rpm nss-pkcs11-devel-3.12.9-12.el6_1.i686.rpm nss-sysinit-3.12.9-12.el6_1.i686.rpm nss-tools-3.12.9-12.el6_1.i686.rpm nss-softokn-3.12.9-3.el6.i686.rpm nss-softokn-devel-3.12.9-3.el6.i686.rpm nss-softokn-freebl-3.12.9-3.el6.i686.rpm nss-softokn-freebl-devel-3.12.9-3.el6.i686.rpm nss-util-3.12.9-1.el6.i686.rpm nss-util-devel-3.12.9-1.el6.i686.rpm x86_64 nss-3.12.9-12.el6_1.i686.rpm nss-3.12.9-12.el6_1.x86_64.rpm nss-sysinit-3.12.9-12.el6_1.x86_64.rpm nss-pkcs11-devel-3.12.9-12.el6_1.x86_64.rpm nss-pkcs11-devel-3.12.9-12.el6_1.i686.rpm nss-debuginfo-3.12.9-12.el6_1.x86_64.rpm nss-debuginfo-3.12.9-12.el6_1.i686.rpm nss-devel-3.12.9-12.el6_1.x86_64.rpm nss-devel-3.12.9-12.el6_1.i686.rpm nss-tools-3.12.9-12.el6_1.x86_64.rpm nss-softokn-3.12.9-3.el6.i686.rpm nss-softokn-3.12.9-3.el6.x86_64.rpm nss-softokn-devel-3.12.9-3.el6.i686.rpm nss-softokn-devel-3.12.9-3.el6.x86_64.rpm nss-softokn-freebl-3.12.9-3.el6.i686.rpm nss-softokn-freebl-3.12.9-3.el6.x86_64.rpm nss-softokn-freebl-devel-3.12.9-3.el6.i686.rpm nss-softokn-freebl-devel-3.12.9-3.el6.x86_64.rpm nss-util-3.12.9-1.el6.i686.rpm nss-util-3.12.9-1.el6.x86_64.rpm nss-util-devel-3.12.9-1.el6.i686.rpm nss-util-devel-3.12.9-1.el6.x86_64.rpm - Scientific Linux Development Team . Important nss and nspr security updates for Scientific Linux addressing certificate trust issues.. NSS Update, NSPR Update, Scientific Linux Security. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.