[ubuntu/artful-proposed] nss 2:3.28.4-0ubuntu2 (Accepted)
Marc Deslauriers
marc.deslauriers at ubuntu.com
Fri Jun 16 13:17:15 UTC 2017
nss (2:3.28.4-0ubuntu2) artful; urgency=medium
* SECURITY UPDATE: DoS via empty SSLv2 messages
- debian/patches/CVE-2017-7502.patch: reject broken v2 records in
nss/lib/ssl/ssl3gthr.c, nss/lib/ssl/ssldef.c, nss/lib/ssl/sslimpl.h,
added tests to nss/gtests/ssl_gtest/ssl_gather_unittest.cc,
nss/gtests/ssl_gtest/ssl_gtest.gyp, nss/gtests/ssl_gtest/manifest.mn,
nss/gtests/ssl_gtest/ssl_v2_client_hello_unittest.cc.
- CVE-2017-7502
Date: Fri, 16 Jun 2017 08:12:38 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/nss/2:3.28.4-0ubuntu2
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 16 Jun 2017 08:12:38 -0400
Source: nss
Binary: libnss3 libnss3-tools libnss3-dev libnss3-dbg
Architecture: source
Version: 2:3.28.4-0ubuntu2
Distribution: artful
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description:
libnss3 - Network Security Service libraries
libnss3-dbg - Debugging symbols for the Network Security Service libraries
libnss3-dev - Development files for the Network Security Service libraries
libnss3-tools - Network Security Service tools
Changes:
nss (2:3.28.4-0ubuntu2) artful; urgency=medium
.
* SECURITY UPDATE: DoS via empty SSLv2 messages
- debian/patches/CVE-2017-7502.patch: reject broken v2 records in
nss/lib/ssl/ssl3gthr.c, nss/lib/ssl/ssldef.c, nss/lib/ssl/sslimpl.h,
added tests to nss/gtests/ssl_gtest/ssl_gather_unittest.cc,
nss/gtests/ssl_gtest/ssl_gtest.gyp, nss/gtests/ssl_gtest/manifest.mn,
nss/gtests/ssl_gtest/ssl_v2_client_hello_unittest.cc.
- CVE-2017-7502
Checksums-Sha1:
1f42b65328ff107143901ad26743a23092737a44 2332 nss_3.28.4-0ubuntu2.dsc
b1b49763711efb6765f882445f2352f5aa862ae0 28972 nss_3.28.4-0ubuntu2.debian.tar.xz
509f84588729993359395125623018290a4071d0 5746 nss_3.28.4-0ubuntu2_source.buildinfo
Checksums-Sha256:
a894d5d04447a9bde2cab13c3144c1b93975ae7b453aed3351c3f08db08456c0 2332 nss_3.28.4-0ubuntu2.dsc
dcc22bd58cd4844489d6ef3945afd88f4cf7b00cb49864de1bec6cab6b3cdbf7 28972 nss_3.28.4-0ubuntu2.debian.tar.xz
a8072646e3e93483307ed11f6f908e2acb4d17999cc8b21e256cfb1338fc5970 5746 nss_3.28.4-0ubuntu2_source.buildinfo
Files:
4097f59aa222235b177965ae5f6dd31a 2332 libs optional nss_3.28.4-0ubuntu2.dsc
a7910c5911c44cc690ab54bbbaa76e7a 28972 libs optional nss_3.28.4-0ubuntu2.debian.tar.xz
939f6b4c9edc7a6569294a5f3023b2f1 5746 libs optional nss_3.28.4-0ubuntu2_source.buildinfo
Original-Maintainer: Maintainers of Mozilla-related packages <pkg-mozilla-maintainers at lists.alioth.debian.org>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJZQ9gTAAoJEGVp2FWnRL6THxMQAI4L+OYOqmRv65AE61L0jRLH
a7Wgo5GXjdqcUXOs7ZO1tFR9d7q2XWUTvQKHFiw2jCc5ewrWnFch1ekaQ37t9x8S
GL2efqODraykCMx5bmBCSQSm7UYsHuadmgK5gjvegiyyRVy8hf49ZD2Bp19aMxdn
gGYI8r8z+VETKJIQTzL3MJMp1EYShxBjm0s4ge58QKw3Aya6b+bVANynIsOcTfR+
kLPuJAIB8CLSrBa1MLQMWUk9C70la/m9UuQRlPVYMZlySEQlL6WlPIMkmAlbuFPo
ZfZ6v0I4sQnoyAknf2NfiH8wHcG80mz6pCmwPvg/f4UYW/GL2qP3CB+LTkJh7izG
BL1gedJ2A6CprZT1fRWJQ+2puACcyfP2MWwse3KfmVRm+YnSo4y4e2w4CnObRWwz
YueYWi6pDCSW6VL9Ul7UImjNuciRQKBM7t4i6ef5Tutb1YQ4DnlneAyc340swap/
2gl6bPOE7y/CaC9rY9ZOthYBpmmk8GdfZgbqO87UAJk6R+q6yuPRkSiZrg4/Avgx
wZr4yIu8Q/RMddu0yrppqzYy1yUvyTmBwtkq2bvuRBP2yugXZbN+CyOaaPjrZXia
PrZPX05rnxQGNGcBfJz/9Jxiuu89+dNRyvTFBAjcb4PTaHdUq3dHW+EwHXo2USqX
Qt5R9JM9vEKDHEbL0DT1
=PLHM
-----END PGP SIGNATURE-----
More information about the Artful-changes
mailing list