libnss: security bump to version 3.17.3
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Tue, 16 Dec 2014 11:12:54 +0000 (08:12 -0300)
committerPeter Korsgaard <peter@korsgaard.com>
Tue, 16 Dec 2014 22:48:32 +0000 (23:48 +0100)
commit6efc256a7762ed388ca57d809ceb3fc9f6776b7d
treef474acf90dac943ee9d57f5fe731595d2c1cdda4
parent267899db398439b9068c3e13c20209171d5936a1
libnss: security bump to version 3.17.3

Fixes CVE-2014-1569 - The definite_length_decoder function in
lib/util/quickder.c in Mozilla Network Security Services (NSS) before
3.16.2.4 and 3.17.x before 3.17.3 does not ensure that the DER encoding
of an ASN.1 length is properly formed, which allows remote attackers to
conduct data-smuggling attacks by using a long byte sequence for an
encoding.

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/libnss/libnss.hash
package/libnss/libnss.mk