SCIENTIFIC-LINUX-ERRATA Archives

July 2012

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Patrick Riehecky <[log in to unmask]>
Reply To:
Date:
Wed, 18 Jul 2012 11:36:34 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (71 lines)
Synopsis:    Moderate: nss, nspr, and nss-util security, bug fix, and enhancement update
Issue Date:  2012-07-17
CVE Numbers: CVE-2012-0441


Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.

A flaw was found in the way the ASN.1 (Abstract Syntax Notation One)
decoder in NSS handled zero length items. This flaw could cause the decoder
to incorrectly skip or replace certain items with a default value, or could
cause an application to crash if, for example, it received a
specially-crafted OCSP (Online Certificate Status Protocol) response.
(CVE-2012-0441)

The nspr package has been upgraded to upstream version 4.9.1, which
provides a number of bug fixes and enhancements over the previous version.

The nss-util package has been upgraded to upstream version 3.13.5, which
provides a number of bug fixes and enhancements over the previous version.

The nss package has been upgraded to upstream version 3.13.5, which
provides a number of bug fixes and enhancements over the previous version.

All NSS, NSPR, and nss-util users are advised to upgrade to these updated
packages, which correct these issues and add these enhancements. After
installing this update, applications using NSS, NSPR, or nss-util must be
restarted for this update to take effect.

SL6:
  i386
     nspr-4.9.1-2.el6_3.i686.rpm
     nspr-debuginfo-4.9.1-2.el6_3.i686.rpm
     nspr-devel-4.9.1-2.el6_3.i686.rpm
     nss-3.13.5-1.el6_3.i686.rpm
     nss-debuginfo-3.13.5-1.el6_3.i686.rpm
     nss-devel-3.13.5-1.el6_3.i686.rpm
     nss-pkcs11-devel-3.13.5-1.el6_3.i686.rpm
     nss-sysinit-3.13.5-1.el6_3.i686.rpm
     nss-tools-3.13.5-1.el6_3.i686.rpm
     nss-util-3.13.5-1.el6_3.i686.rpm
     nss-util-debuginfo-3.13.5-1.el6_3.i686.rpm
     nss-util-devel-3.13.5-1.el6_3.i686.rpm
  x86_64
     nspr-4.9.1-2.el6_3.i686.rpm
     nspr-4.9.1-2.el6_3.x86_64.rpm
     nspr-debuginfo-4.9.1-2.el6_3.i686.rpm
     nspr-debuginfo-4.9.1-2.el6_3.x86_64.rpm
     nspr-devel-4.9.1-2.el6_3.i686.rpm
     nspr-devel-4.9.1-2.el6_3.x86_64.rpm
     nss-3.13.5-1.el6_3.i686.rpm
     nss-3.13.5-1.el6_3.x86_64.rpm
     nss-debuginfo-3.13.5-1.el6_3.i686.rpm
     nss-debuginfo-3.13.5-1.el6_3.x86_64.rpm
     nss-devel-3.13.5-1.el6_3.i686.rpm
     nss-devel-3.13.5-1.el6_3.x86_64.rpm
     nss-pkcs11-devel-3.13.5-1.el6_3.i686.rpm
     nss-pkcs11-devel-3.13.5-1.el6_3.x86_64.rpm
     nss-sysinit-3.13.5-1.el6_3.x86_64.rpm
     nss-tools-3.13.5-1.el6_3.x86_64.rpm
     nss-util-3.13.5-1.el6_3.i686.rpm
     nss-util-3.13.5-1.el6_3.x86_64.rpm
     nss-util-debuginfo-3.13.5-1.el6_3.i686.rpm
     nss-util-debuginfo-3.13.5-1.el6_3.x86_64.rpm
     nss-util-devel-3.13.5-1.el6_3.i686.rpm
     nss-util-devel-3.13.5-1.el6_3.x86_64.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2