|
|
Subscribe / Log in / New account

Debian alert DLA-2058-1 (nss)

From:  Markus Koschany <apo@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 2058-1] nss security update
Date:  Tue, 7 Jan 2020 00:25:44 +0100
Message-ID:  <9e85ed4c-6e3c-5bc9-7770-60e3bb012841@debian.org>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Package : nss Version : 2:3.26-1+debu8u10 CVE ID : CVE-2019-17006 It was found that certain cryptographic primitives in nss, the Network Security Service libraries, did not check the length of the input text. This could result in a potential heap-based buffer overflow. For Debian 8 "Jessie", this problem has been fixed in version 2:3.26-1+debu8u10. We recommend that you upgrade your nss packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAl4TwfhfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQACgkQ2a0UuVE7 UeQhZw//a2A1sKS8hqcdf8q/RM1uX6Gie9KsGPuhCPdAebi5SLcSpS9NewAcbuI3 cjfjWWWi4hHOCJYCe2UlWirBUl9/PwZikGpEWPTL2IVfBXG6zg61e16MH+EpSW3J QRzKZyZv1rkNyWOiBTKOu4+/zOjN4Yjsiltt2LnawE9orhtwnVJfFdUaVsrr8SzT XXroPAsoDyb+kgo8fapkgmLCJTQ6V0FVYq5bs5CLZwCgSWxXWmsQXzdHnsFXbk5A dv6Nuh6Qt8qFU0Z3nH+nlR1MIkh1W2ft+Y79Kzu2ebbh5yuWbi5LMeZzZEDVFQkG EEeNy8v7J/kf/2lNyvtVqZWfEfIdmxbaX38VsdcVkrCBsSqO3Cj8dHYagwaSg70j voBIi5eOfSVUkD+7s/ffM96xu1Q/tpMfwvYmNBF4UgcZbqL7xmyyUgkDE3AjiRqi e5jLDAWxiycABJeB5T8FueYvflBlPLAISjlNP92sMp2qMg1UgJEedcolv76vEYAE BC4MSx1P17CGTHGaZSqF/kM2PVwnrmuecey4Dp0JE8CvgroOt5zN+HtYuuykW//D cpzeWDJ++2m1xGcqVLfRAQY7pfbpUMAGGhscAR0L7BnSpTU3bRJ359k3V9P5x5yF lFN8WzA3NpZF9Q24hniYaRqbd93LJj5HEPulEOLCe4y5ih78eLc= =Vma1 -----END PGP SIGNATURE-----


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds