Debian Security Advisory

DLA-676-1 nspr -- LTS security update

Date Reported:
25 Oct 2016
Affected Packages:
nspr
Vulnerable:
Yes
Security database references:
No other external database security references currently available.
More information:

The Network Security Service (NSS) libraries uses environment variables to configure lots of things, some of which refer to file system locations. Others can be degrade the operation of NSS in various ways, forcing compatibility modes and so on.

Previously, these environment variables were not ignored SUID binaries. This version of NetScape Portable Runtime Library (NSPR) introduce a new API, PR_GetEnVSecure, to address this.

Both NSPR and NSS need to be upgraded to address this problem.

For Debian 7 Wheezy, these problems have been fixed in NSPR version 4.12-1+deb7u1.

We recommend that you upgrade your nspr packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS