[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CESA-2012:1091 -- centos 6 nss,nss-util,nspr

ID: oval:org.secpod.oval:def:202397Date: (C)2012-07-21   (M)2023-07-28
Class: PATCHFamily: unix




Network Security Services is a set of libraries designed to support the cross-platform development of security-enabled client and server applications. Netscape Portable Runtime provides platform independence for non-GUI operating system facilities. A flaw was found in the way the ASN.1 decoder in NSS handled zero length items. This flaw could cause the decoder to incorrectly skip or replace certain items with a default value, or could cause an application to crash if, for example, it received a specially-crafted OCSP response. The nspr package has been upgraded to upstream version 4.9.1, which provides a number of bug fixes and enhancements over the previous version. The nss-util package has been upgraded to upstream version 3.13.5, which provides a number of bug fixes and enhancements over the previous version. The nss package has been upgraded to upstream version 3.13.5, which provides a number of bug fixes and enhancements over the previous version. All NSS, NSPR, and nss-util users are advised to upgrade to these updated packages, which correct these issues and add these enhancements. After installing this update, applications using NSS, NSPR, or nss-util must be restarted for this update to take effect.

Platform:
CentOS 6
Product:
nspr
nss
nss-util
Reference:
CESA-2012:1091
CVE-2012-0441
CVE    1
CVE-2012-0441
CPE    4
cpe:/a:nss:network_security_services
cpe:/a:nss:nss-util
cpe:/a:mozilla:netscape_portable_runtime
cpe:/o:centos:centos:6
...

© SecPod Technologies