Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2017-1364

Опубликовано: 30 мая 2017
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2017-1364: nss security and bug fix update (IMPORTANT)

[3.28.4-3.0.1]

  • Added nss-vendor.patch to change vendor
  • Temporarily disable some tests until expired PayPalEE.cert is renewed

[3.28.4-3]

  • Fix zero-length record treatment for stream ciphers and SSLv2

[3.28.4-2]

  • Include CKBI 2.14 and updated CA constraints from NSS 3.28.5

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

nss

3.28.4-3.0.1.el6_9

nss-devel

3.28.4-3.0.1.el6_9

nss-pkcs11-devel

3.28.4-3.0.1.el6_9

nss-sysinit

3.28.4-3.0.1.el6_9

nss-tools

3.28.4-3.0.1.el6_9

Oracle Linux i686

nss

3.28.4-3.0.1.el6_9

nss-devel

3.28.4-3.0.1.el6_9

nss-pkcs11-devel

3.28.4-3.0.1.el6_9

nss-sysinit

3.28.4-3.0.1.el6_9

nss-tools

3.28.4-3.0.1.el6_9

Oracle Linux sparc64

nss

3.28.4-3.0.1.el6_9

nss-devel

3.28.4-3.0.1.el6_9

nss-pkcs11-devel

3.28.4-3.0.1.el6_9

nss-sysinit

3.28.4-3.0.1.el6_9

nss-tools

3.28.4-3.0.1.el6_9

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote attacker.

CVSS3: 7.5
redhat
больше 8 лет назад

Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote attacker.

CVSS3: 7.5
nvd
больше 8 лет назад

Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote attacker.

CVSS3: 7.5
debian
больше 8 лет назад

Null pointer dereference vulnerability in NSS since 3.24.0 was found w ...

CVSS3: 7.5
github
больше 3 лет назад

Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote attacker.