Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2014-0916

Опубликовано: 22 июл. 2014
Источник: oracle-oval
Платформа: Oracle Linux 5
Платформа: Oracle Linux 7

Описание

ELSA-2014-0916: nss and nspr security update (CRITICAL)

nspr [4.10.2-4]

  • Rebase to nspr-4.10.6
  • Resolves: Bug 1116199

[4.10.2-3]

  • Retagging
  • Resolves: rhbz#1032466

nss [3.15.3-7]

  • Remove an unused patch
  • Related: Bug 1116199

[3.15.3-6]

  • Fix race-condition in certificate validation
  • Resolves: Bug 1116199

[3.15.3-5]

  • Remove two unused patches
  • Resolves: Bug 1042683 - nss: Mis-issued ANSSI/DCSSI certificate (MFSA 2013-117)

Обновленные пакеты

Oracle Linux 5

Oracle Linux ia64

nspr

4.10.6-1.el5_10

nspr-devel

4.10.6-1.el5_10

nss

3.15.3-7.el5_10

nss-devel

3.15.3-7.el5_10

nss-pkcs11-devel

3.15.3-7.el5_10

nss-tools

3.15.3-7.el5_10

Oracle Linux x86_64

nspr

4.10.6-1.el5_10

nspr-devel

4.10.6-1.el5_10

nss

3.15.3-7.el5_10

nss-devel

3.15.3-7.el5_10

nss-pkcs11-devel

3.15.3-7.el5_10

nss-tools

3.15.3-7.el5_10

Oracle Linux i386

nspr

4.10.6-1.el5_10

nspr-devel

4.10.6-1.el5_10

nss

3.15.3-7.el5_10

nss-devel

3.15.3-7.el5_10

nss-pkcs11-devel

3.15.3-7.el5_10

nss-tools

3.15.3-7.el5_10

Oracle Linux 7

Oracle Linux x86_64

nspr

4.10.6-1.el7_0

nspr-devel

4.10.6-1.el7_0

nss

3.15.4-7.0.1.el7_0

nss-devel

3.15.4-7.0.1.el7_0

nss-pkcs11-devel

3.15.4-7.0.1.el7_0

nss-sysinit

3.15.4-7.0.1.el7_0

nss-tools

3.15.4-7.0.1.el7_0

Связанные CVE

Связанные уязвимости

ubuntu
около 11 лет назад

Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a trust domain.

redhat
около 11 лет назад

Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a trust domain.

nvd
около 11 лет назад

Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a trust domain.

debian
около 11 лет назад

Use-after-free vulnerability in the CERT_DestroyCertificate function i ...

github
около 3 лет назад

Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a trust domain.