Debian-LTS alert DLA-677-1 (nss)
From: | Ola Lundqvist <opal@debian.org> | |
To: | debian-lts-announce@lists.debian.org | |
Subject: | [SECURITY] [DLA 677-1] nss security update | |
Date: | Tue, 25 Oct 2016 22:01:38 +0200 | |
Message-ID: | <20161025200138.GA3709@inguza.net> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Package : nss Version : 3.26-1+debu7u1 The Network Security Service (NSS) libraries uses environment variables to configure lots of things, some of which refer to file system locations. Others can be degrade the operation of NSS in various ways, forcing compatibility modes and so on. Previously, these environment variables were not ignored SUID binaries. This version of NetScape Portable Runtime Library (NSPR) introduce a new API, PR_GetEnVSecure, to address this. Both NSPR and NSS need to be upgraded to address this problem. For Debian 7 "Wheezy", these problems have been fixed in NSS version 3.26-1+debu7u1. We recommend that you upgrade your nss packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS - -- --------------------- Ola Lundqvist --------------------------- / opal@debian.org \ | ola@inguza.com | | http://inguza.com/ | \ gpg/f.p.: 22F2 32C6 B1E0 F4BF 2B26 0A6A 5E90 DCFA 9426 876F / --------------------------------------------------------------- -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBCAAGBQJYD7oiAAoJEF6Q3PqUJodvOCIP/2xKNKiaMwPpcUEBsjj3/XBK F7760JDGnSJckCouer/PMb0mr3nJ3t12T3dM/OUboTjAaJByCGGCKkU1JO1H8oyU 0OFBqFTEh+UYv80KVLPELWjqAdOXX5RtUVED8ObKzJfsrUcHyalBHX/qjgcpKAx2 Cc7ARTveWJzXIhC8Ng657iTh2U2s0zu/1PANnMh8t8q+6L9VzSX1XMOMMQhaBnwo qksrkcHGDyXSl6YzfzSw/XfZwdRvV0Jc/3/mWI2MsLGV2Yn3Lo5T2y0wtwapMUbv Qu/w746cLt4p30MU26+a9lwJbTAswfsFLXm8KiZs7TZXuVkfLefq4rhs5cGj0SV4 n8fqRl8C8NSDnjuAvETffUaHdOyuDET2wgKhg+oZi5Jji3qSwUhsh+XpDJhr3fjS BUB4C6UwwHh9kk6g3WRANm95J2Xf20r1fgFufHG6GzWUyNeZ8UNjDBmBU7afbu0O kyWdHdFodp2OKu5yoO93qBl1dB63KjnE/xQ2ib0c55xHeGM1PO4kPBZ3VQI1k5zB ZbI45trF3KFG1XgyiOs9E0EHErqcrdSkBdz+uh1haCLzeg9ofg9DTVYXPZkBh4A7 aFBQW4kcw0tpuqct2V5VC/4Ad5gyHd2BdXCEjw4qaZCgU3TuI2XgBY+eWTYJIZgK J2Vwsu1Q4htU0P+v+WKR =w98w -----END PGP SIGNATURE-----