Synopsis:          Moderate: mod_nss security update
Advisory ID:       SLSA-2013:1779-1
Issue Date:        2013-12-03
CVE Numbers:       CVE-2013-4566
--

A flaw was found in the way mod_nss handled the NSSVerifyClient setting
for the per-directory context. When configured to not require a client
certificate for the initial connection and only require it for a specific
directory, mod_nss failed to enforce this requirement and allowed a client
to access the directory when no valid client certificate was provided.
(CVE-2013-4566)

The httpd service must be restarted for this update to take effect.
--

SL5
  x86_64
    mod_nss-1.0.8-8.el5_10.x86_64.rpm
    mod_nss-debuginfo-1.0.8-8.el5_10.x86_64.rpm
  i386
    mod_nss-1.0.8-8.el5_10.i386.rpm
    mod_nss-debuginfo-1.0.8-8.el5_10.i386.rpm
SL6
  x86_64
    mod_nss-1.0.8-19.el6_5.x86_64.rpm
    mod_nss-debuginfo-1.0.8-19.el6_5.x86_64.rpm
  i386
    mod_nss-1.0.8-19.el6_5.i686.rpm
    mod_nss-debuginfo-1.0.8-19.el6_5.i686.rpm

- Scientific Linux Development Team