[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 677-1] nss security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Package        : nss
Version        : 3.26-1+debu7u1

The Network Security Service (NSS) libraries uses 
environment variables to configure lots of things, some of which refer to
file system locations. Others can be degrade the operation of NSS in various
ways, forcing compatibility modes and so on.

Previously, these environment variables were not ignored SUID
binaries. This version of NetScape Portable Runtime Library (NSPR)
introduce a new API, PR_GetEnVSecure, to address this.

Both NSPR and NSS need to be upgraded to address this problem.

For Debian 7 "Wheezy", these problems have been fixed in NSS version
3.26-1+debu7u1.

We recommend that you upgrade your nss packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

- -- 
 --------------------- Ola Lundqvist ---------------------------
/  opal@debian.org                                              \
|  ola@inguza.com                                               |
|  http://inguza.com/                                           |
\  gpg/f.p.: 22F2 32C6 B1E0 F4BF 2B26  0A6A 5E90 DCFA 9426 876F /
 ---------------------------------------------------------------
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQIcBAEBCAAGBQJYD7oiAAoJEF6Q3PqUJodvOCIP/2xKNKiaMwPpcUEBsjj3/XBK
F7760JDGnSJckCouer/PMb0mr3nJ3t12T3dM/OUboTjAaJByCGGCKkU1JO1H8oyU
0OFBqFTEh+UYv80KVLPELWjqAdOXX5RtUVED8ObKzJfsrUcHyalBHX/qjgcpKAx2
Cc7ARTveWJzXIhC8Ng657iTh2U2s0zu/1PANnMh8t8q+6L9VzSX1XMOMMQhaBnwo
qksrkcHGDyXSl6YzfzSw/XfZwdRvV0Jc/3/mWI2MsLGV2Yn3Lo5T2y0wtwapMUbv
Qu/w746cLt4p30MU26+a9lwJbTAswfsFLXm8KiZs7TZXuVkfLefq4rhs5cGj0SV4
n8fqRl8C8NSDnjuAvETffUaHdOyuDET2wgKhg+oZi5Jji3qSwUhsh+XpDJhr3fjS
BUB4C6UwwHh9kk6g3WRANm95J2Xf20r1fgFufHG6GzWUyNeZ8UNjDBmBU7afbu0O
kyWdHdFodp2OKu5yoO93qBl1dB63KjnE/xQ2ib0c55xHeGM1PO4kPBZ3VQI1k5zB
ZbI45trF3KFG1XgyiOs9E0EHErqcrdSkBdz+uh1haCLzeg9ofg9DTVYXPZkBh4A7
aFBQW4kcw0tpuqct2V5VC/4Ad5gyHd2BdXCEjw4qaZCgU3TuI2XgBY+eWTYJIZgK
J2Vwsu1Q4htU0P+v+WKR
=w98w
-----END PGP SIGNATURE-----


Reply to: