Debian Security Advisory

DLA-344-1 nspr -- LTS security update

Date Reported:
19 Nov 2015
Affected Packages:
nspr
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2015-7183.
More information:

Google security engineer Ryan Sleevi found a vulnerability in the NetScape Portable Runtime Library (NSPR). NSPR allocated memory without specific checks, making it possible for remote attackers to cause a Denial of Service or execute arbitrary code.

For Debian 6 Squeeze, this issue have been fixed in nspr version 4.8.6-1+squeeze3. We recommend that you upgrade your nspr packages.