Debian Security Advisory

DLA-354-1 nss -- LTS security update

Date Reported:
29 Nov 2015
Affected Packages:
nss
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2015-7181, CVE-2015-7182.
More information:

Several vulnerabilities have been discovered in nss, the Mozilla Network Security Service library. The Common Vulnerabilities and Exposures project identifies the following problems:

  • CVE-2015-7181

    The sec_asn1d_parse_leaf function improperly restricts access to an unspecified data structure, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data, related to a "use-after-poison" issue.

  • CVE-2015-7182

    A Heap-based buffer overflow in the ASN.1 decoder allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data.

For the oldoldstable distribution (squeeze), these problems have been fixed in version 3.12.8-1+squeeze13.

We recommend that you upgrade your nss packages.