SCIENTIFIC-LINUX-ERRATA Archives

December 2013

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Mon, 9 Dec 2013 16:01:16 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (33 lines)
Synopsis:          Moderate: mod_nss security update
Advisory ID:       SLSA-2013:1779-1
Issue Date:        2013-12-03
CVE Numbers:       CVE-2013-4566
--

A flaw was found in the way mod_nss handled the NSSVerifyClient setting
for the per-directory context. When configured to not require a client
certificate for the initial connection and only require it for a specific
directory, mod_nss failed to enforce this requirement and allowed a client
to access the directory when no valid client certificate was provided.
(CVE-2013-4566)

The httpd service must be restarted for this update to take effect.
--

SL5
  x86_64
    mod_nss-1.0.8-8.el5_10.x86_64.rpm
    mod_nss-debuginfo-1.0.8-8.el5_10.x86_64.rpm
  i386
    mod_nss-1.0.8-8.el5_10.i386.rpm
    mod_nss-debuginfo-1.0.8-8.el5_10.i386.rpm
SL6
  x86_64
    mod_nss-1.0.8-19.el6_5.x86_64.rpm
    mod_nss-debuginfo-1.0.8-19.el6_5.x86_64.rpm
  i386
    mod_nss-1.0.8-19.el6_5.i686.rpm
    mod_nss-debuginfo-1.0.8-19.el6_5.i686.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2