Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-3280

Опубликовано: 04 авг. 2020
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2020-3280: nss and nspr security, bug fix, and enhancement update (MODERATE)

nspr [4.25.0-2]

  • Rebuild

[4.25.0-1]

  • Update to NSPR 4.25

nss [3.53.1-11]

  • Fix issue with upgradedb where upgradedb expects standard to generate dbm databases, not sql databases (default in RHEL8)

[3.53.1-10]

  • Disable dh timing test because it's unreliable on s390

[3.53.1-9]

  • Explicitly enable upgradedb/sharedb test cycles

[3.53.1-8]

  • Disable Delegated Credentials for TLS

[3.53.1-7]

  • Fix attribute decryption issue where the private key components integrity check on private attributes where not being checked.

[3.53.1-6]

  • Update nss-rsa-pkcs1-sigalgs.patch to the upstream version

[3.53.1-5]

  • Include required checks for dh and ecdh key generation in FIPS mode.

[3.53.1-4]

  • Add better checks for dh derive operations in FIPS mode.

[3.53.1-3]

  • Disable NSS_HASH_ALG_SUPPORT as well for MD5 (#1849938)
  • Adjust for update-crypto-policies packaging change (#1848649)
  • Fix compilation with -Werror=strict-prototypes (#1843417)

[3.53.1-2]

  • Fix regression in MD5 disablement (#1849938)
  • Include rsa_pkcs1_* in signature_algorithms extension (#1847945)

[3.53.1-1]

  • Update to NSS 3.53.1

[3.53.0-1]

  • Update to NSS 3.53

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

nspr

4.25.0-2.el8_2

nspr-devel

4.25.0-2.el8_2

nss

3.53.1-11.el8_2

nss-devel

3.53.1-11.el8_2

nss-softokn

3.53.1-11.el8_2

nss-softokn-devel

3.53.1-11.el8_2

nss-softokn-freebl

3.53.1-11.el8_2

nss-softokn-freebl-devel

3.53.1-11.el8_2

nss-sysinit

3.53.1-11.el8_2

nss-tools

3.53.1-11.el8_2

nss-util

3.53.1-11.el8_2

nss-util-devel

3.53.1-11.el8_2

Oracle Linux x86_64

nspr

4.25.0-2.el8_2

nspr-devel

4.25.0-2.el8_2

nss

3.53.1-11.el8_2

nss-devel

3.53.1-11.el8_2

nss-softokn

3.53.1-11.el8_2

nss-softokn-devel

3.53.1-11.el8_2

nss-softokn-freebl

3.53.1-11.el8_2

nss-softokn-freebl-devel

3.53.1-11.el8_2

nss-sysinit

3.53.1-11.el8_2

nss-tools

3.53.1-11.el8_2

nss-util

3.53.1-11.el8_2

nss-util-devel

3.53.1-11.el8_2

Связанные уязвимости

rocky
больше 5 лет назад

Moderate: nss and nspr security, bug fix, and enhancement update

oracle-oval
около 5 лет назад

ELSA-2020-4076: nss and nspr security, bug fix, and enhancement update (MODERATE)

suse-cvrf
больше 5 лет назад

Security update for mozilla-nspr, mozilla-nss

suse-cvrf
больше 5 лет назад

Security update for mozilla-nspr, mozilla-nss

CVSS3: 9.8
ubuntu
около 5 лет назад

In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.