|
|
Log in / Subscribe / Register

Debian-LTS alert DLA-427-1 (nss)

From:  Guido Günther <agx@sigxcpu.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 427-1] nss security update
Date:  Wed, 24 Feb 2016 07:59:57 +0100
Message-ID:  <20160224065957.GA2453@bogon.m.sigxcpu.org>

Package : nss Version : 3.12.8-1+squeeze14 CVE ID : CVE-2016-1938 The s_mp_div function in Mozilla Network Security Services (NSS) before 3.21, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging use of the (1) mp_div or (2) mp_exptmod function. For the oldoldstable distribution (squeeze), these problem has been fixed in version 3.12.8-1+squeeze14. We recommend that you upgrade your nss packages.


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds