[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DSA 5062-1] nss security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5062-1                   security@debian.org
https://www.debian.org/security/                     Salvatore Bonaccorso
January 25, 2022                      https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : nss
CVE ID         : CVE-2022-22747

Tavis Ormandy discovered that incorrect parsing of pkcs7 sequences in
nss, the Mozilla Network Security Service library, may result in denial
of service.

For the oldstable distribution (buster), this problem has been fixed
in version 2:3.42.1-1+deb10u5.

For the stable distribution (bullseye), this problem has been fixed in
version 2:3.61-1+deb11u2.

We recommend that you upgrade your nss packages.

For the detailed security status of nss please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/nss

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmHwc+lfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0Tr6Q//daEqoVUkJVZDJjpaX/HEu8v5bJ6yQoR1/5B8tbP+AceuC/fCXb9Hvv8o
/zUeAHGC0i3kdeNcvgf3klsCVWeRcCtspwIeYdFz7tE9kNEYS4Kg0+W9Fh1Dv5fg
pHtMLcLQWkQT3evGV0eEggsgRrC2uPUoLtuN1+7vQoSMRLjLR42/xR01ZqmvnQ7z
rSIkR7R4QV3mVA+tPQ/crOvgAUe7ivYZuofqjXslwI/3bTo87Cf8+TK5imWfw811
oNIxLFOlk5e/59vUFh24dSdV4lTk3rBQe63Od0LV0icsXQyteAs7jlqIQCW0vwLp
v4Q+5fTljHMELHWJtsxvpl3PFzR32+Zz6dlf8daAYSipRjNzTth+iZ+JiBqXhg4i
vvCYDPgoma6r6h1IC5IW61lVLUeXhEF9QsR9fmia9geBFnMV3MrHA96txui/7stt
pa60CtVW8/0OrvwEJ1xjPXVLY8ZHL3P+oekV1hPp1A+hK9ZDhW/D208bBfu+177g
Znnda4+LDsj4wPjvMvJLweDmYbdvT9//A8jYbqvkhKI5fajtBsUvZqjg4umnBvC4
zhYBiaqm3by0k5qwmsxpF2gdsrbo+kug7UD2Mjh2u2mzFu3yGq+pD4bJjNefPJE9
Y85irnPcYa+tKvbGHo8dicrSfo+Tnt49gZRCzCD0rGIzxTiOOow=
=635D
-----END PGP SIGNATURE-----


Reply to: