Debian Security Advisory

DLA-1857-1 nss -- LTS security update

Date Reported:
20 Jul 2019
Affected Packages:
nss
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2019-11719, CVE-2019-11729.
More information:

Vulnerabilities have been discovered in nss, the Mozilla Network Security Service library.

  • CVE-2019-11719:

    Out-of-bounds read when importing curve25519 private key

    When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library. This could lead to information disclosure.

  • CVE-2019-11729:

    Empty or malformed p256-ECDH public keys may trigger a segmentation fault

    Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memory and used.

For Debian 8 Jessie, these problems have been fixed in version 2:3.26-1+debu8u5.

We recommend that you upgrade your nss packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS