libnss: security bump to version 3.22.2
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Wed, 9 Mar 2016 11:41:20 +0000 (08:41 -0300)
committerPeter Korsgaard <peter@korsgaard.com>
Wed, 9 Mar 2016 12:14:13 +0000 (13:14 +0100)
commit09f0b8c353d6b7886dd5cab3deee0cc9625b6eed
treeb88c635819dba0273f35be45189f4c8cc0008267
parentc6e635735dee76f7103f3e30f68e4f2cbf1d1226
libnss: security bump to version 3.22.2

Fixes:
CVE-2016-1950 - heap-based buffer overflow related to the parsing of
certain ASN.1 structures. An attacker could create a specially-crafted
certificate which, when parsed by NSS, would cause a crash or execution
of arbitrary code with the permissions of the user.

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/libnss/libnss.hash
package/libnss/libnss.mk