Debian Security Advisory
DSA-2490-1 nss -- denial of service
- Date Reported:
- 07 Jun 2012
- Affected Packages:
- nss
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2012-0441.
- More information:
-
Kaspar Brand discovered that Mozilla's Network Security Services (NSS) libraries did insufficient length checking in the QuickDER decoder, allowing to crash a program using the libraries.
For the stable distribution (squeeze), this problem has been fixed in version 3.12.8-1+squeeze5.
For the testing distribution (wheezy) and unstable distribution (sid), this problem has been fixed in version 2:3.13.4-3.
We recommend that you upgrade your nss packages.