[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 676-1] nspr security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Package        : nspr
Version        : 4.12-1+deb7u1

The Network Security Service (NSS) libraries uses 
environment variables to configure lots of things, some of which refer to
file system locations. Others can be degrade the operation of NSS in various
ways, forcing compatibility modes and so on.

Previously, these environment variables were not ignored SUID
binaries. This version of NetScape Portable Runtime Library (NSPR)
introduce a new API, PR_GetEnVSecure, to address this.

Both NSPR and NSS need to be upgraded to address this problem.

For Debian 7 "Wheezy", these problems have been fixed in NSPR version
4.12-1+deb7u1.

We recommend that you upgrade your nspr packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

- -- 
 --------------------- Ola Lundqvist ---------------------------
/  opal@debian.org                                              \
|  ola@inguza.com                                               |
|  http://inguza.com/                                           |
\  gpg/f.p.: 22F2 32C6 B1E0 F4BF 2B26  0A6A 5E90 DCFA 9426 876F /
 ---------------------------------------------------------------
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQIcBAEBCAAGBQJYD7LdAAoJEF6Q3PqUJodvn78QAKvztIR7RzHLstO6GKf6vwa6
32hH9Z4lfqFpkEB2b90iWJOMi3ZHX1F3qsHRLzckBvDC5KpnHyrYSNtaZZNrsEbR
lz8M2TaUissNrn2AR9dJPMLPHKKMnaButux6HRROtyxuF8b0A686ubhBe9YLkVhB
rSeYrMAKNmhOeC5J7312yJSkjkJdeHIO2lrDCQtgRGDA5T/P3IoleMkya8ziDIWv
BqpRtHD5hcDCUAG1Lzm9MUObK+5P3SojmZCPDMrhFWfjNjXmw5DZ1GXZTNBQxgIy
6sAtZqFLuTf1xXYwTLm2D69E1WbErxf1PwNHUCJfZM3LnXMMt8HOiuIc++oZxPXP
MdSLmPRpbYqFfRMb/FZZ7snL/c03eVUkPRcu5Jok9XYuVI3Kr03jNHSTyRHmUBlt
bGVniKGSH2sQeCudZ3F26qLFVht2Vf0dk633euXkWBA6jLQU5rHWrVFSjWMOmKZ6
utiFkfwRU53g7Kumk7q+hYvX6Sv5OQ35O9uXqZNtpwv+AJ5t3sRouXR7+fWln/te
sDl9OzilB8cWo//UxSUYpBLa3SKkUo6wCb015nkzTuVtGwzruX0LycjbGstyvwUq
LDRz2DpDb1F3l/+jO2+hD8X771Wo/zkapqo8n2RCZ2sD2ka07SvF7IPoRtLIwVkl
S+VegyQ2e+Y0MeZftFbH
=OSOF
-----END PGP SIGNATURE-----


Reply to: