MDVSA-2009:197-2 -- Mandriva nssID: oval:org.secpod.oval:def:300704 | Date: (C)2012-01-07 (M)2024-02-19 |
Class: PATCH | Family: unix |
Security issues in nss prior to 3.12.3 could lead to a man-in-the-middle attack via a spoofed X.509 certificate and md2 algorithm flaws , and also cause a denial-of-service and possible code execution via a long domain name in X.509 certificate . This update provides the latest versions of NSS and NSPR libraries which are not vulnerable to those attacks. Update: This update also provides fixed packages for Mandriva Linux 2008.1 and fixes mozilla-thunderbird error messages.
Platform: |
Mandriva Linux 2008.1 |