[ubuntu/artful-proposed] nss 2:3.28.4-0ubuntu2 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Fri Jun 16 13:17:15 UTC 2017


nss (2:3.28.4-0ubuntu2) artful; urgency=medium

  * SECURITY UPDATE: DoS via empty SSLv2 messages
    - debian/patches/CVE-2017-7502.patch: reject broken v2 records in
      nss/lib/ssl/ssl3gthr.c, nss/lib/ssl/ssldef.c, nss/lib/ssl/sslimpl.h,
      added tests to nss/gtests/ssl_gtest/ssl_gather_unittest.cc,
      nss/gtests/ssl_gtest/ssl_gtest.gyp, nss/gtests/ssl_gtest/manifest.mn,
      nss/gtests/ssl_gtest/ssl_v2_client_hello_unittest.cc.
    - CVE-2017-7502

Date: Fri, 16 Jun 2017 08:12:38 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/nss/2:3.28.4-0ubuntu2
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 16 Jun 2017 08:12:38 -0400
Source: nss
Binary: libnss3 libnss3-tools libnss3-dev libnss3-dbg
Architecture: source
Version: 2:3.28.4-0ubuntu2
Distribution: artful
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description:
 libnss3    - Network Security Service libraries
 libnss3-dbg - Debugging symbols for the Network Security Service libraries
 libnss3-dev - Development files for the Network Security Service libraries
 libnss3-tools - Network Security Service tools
Changes:
 nss (2:3.28.4-0ubuntu2) artful; urgency=medium
 .
   * SECURITY UPDATE: DoS via empty SSLv2 messages
     - debian/patches/CVE-2017-7502.patch: reject broken v2 records in
       nss/lib/ssl/ssl3gthr.c, nss/lib/ssl/ssldef.c, nss/lib/ssl/sslimpl.h,
       added tests to nss/gtests/ssl_gtest/ssl_gather_unittest.cc,
       nss/gtests/ssl_gtest/ssl_gtest.gyp, nss/gtests/ssl_gtest/manifest.mn,
       nss/gtests/ssl_gtest/ssl_v2_client_hello_unittest.cc.
     - CVE-2017-7502
Checksums-Sha1:
 1f42b65328ff107143901ad26743a23092737a44 2332 nss_3.28.4-0ubuntu2.dsc
 b1b49763711efb6765f882445f2352f5aa862ae0 28972 nss_3.28.4-0ubuntu2.debian.tar.xz
 509f84588729993359395125623018290a4071d0 5746 nss_3.28.4-0ubuntu2_source.buildinfo
Checksums-Sha256:
 a894d5d04447a9bde2cab13c3144c1b93975ae7b453aed3351c3f08db08456c0 2332 nss_3.28.4-0ubuntu2.dsc
 dcc22bd58cd4844489d6ef3945afd88f4cf7b00cb49864de1bec6cab6b3cdbf7 28972 nss_3.28.4-0ubuntu2.debian.tar.xz
 a8072646e3e93483307ed11f6f908e2acb4d17999cc8b21e256cfb1338fc5970 5746 nss_3.28.4-0ubuntu2_source.buildinfo
Files:
 4097f59aa222235b177965ae5f6dd31a 2332 libs optional nss_3.28.4-0ubuntu2.dsc
 a7910c5911c44cc690ab54bbbaa76e7a 28972 libs optional nss_3.28.4-0ubuntu2.debian.tar.xz
 939f6b4c9edc7a6569294a5f3023b2f1 5746 libs optional nss_3.28.4-0ubuntu2_source.buildinfo
Original-Maintainer: Maintainers of Mozilla-related packages <pkg-mozilla-maintainers at lists.alioth.debian.org>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJZQ9gTAAoJEGVp2FWnRL6THxMQAI4L+OYOqmRv65AE61L0jRLH
a7Wgo5GXjdqcUXOs7ZO1tFR9d7q2XWUTvQKHFiw2jCc5ewrWnFch1ekaQ37t9x8S
GL2efqODraykCMx5bmBCSQSm7UYsHuadmgK5gjvegiyyRVy8hf49ZD2Bp19aMxdn
gGYI8r8z+VETKJIQTzL3MJMp1EYShxBjm0s4ge58QKw3Aya6b+bVANynIsOcTfR+
kLPuJAIB8CLSrBa1MLQMWUk9C70la/m9UuQRlPVYMZlySEQlL6WlPIMkmAlbuFPo
ZfZ6v0I4sQnoyAknf2NfiH8wHcG80mz6pCmwPvg/f4UYW/GL2qP3CB+LTkJh7izG
BL1gedJ2A6CprZT1fRWJQ+2puACcyfP2MWwse3KfmVRm+YnSo4y4e2w4CnObRWwz
YueYWi6pDCSW6VL9Ul7UImjNuciRQKBM7t4i6ef5Tutb1YQ4DnlneAyc340swap/
2gl6bPOE7y/CaC9rY9ZOthYBpmmk8GdfZgbqO87UAJk6R+q6yuPRkSiZrg4/Avgx
wZr4yIu8Q/RMddu0yrppqzYy1yUvyTmBwtkq2bvuRBP2yugXZbN+CyOaaPjrZXia
PrZPX05rnxQGNGcBfJz/9Jxiuu89+dNRyvTFBAjcb4PTaHdUq3dHW+EwHXo2USqX
Qt5R9JM9vEKDHEbL0DT1
=PLHM
-----END PGP SIGNATURE-----


More information about the Artful-changes mailing list