libnss: security bump to version 3.17.3
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Tue, 16 Dec 2014 11:12:54 +0000 (08:12 -0300)
committerPeter Korsgaard <peter@korsgaard.com>
Tue, 16 Dec 2014 22:48:32 +0000 (23:48 +0100)
Fixes CVE-2014-1569 - The definite_length_decoder function in
lib/util/quickder.c in Mozilla Network Security Services (NSS) before
3.16.2.4 and 3.17.x before 3.17.3 does not ensure that the DER encoding
of an ASN.1 length is properly formed, which allows remote attackers to
conduct data-smuggling attacks by using a long byte sequence for an
encoding.

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/libnss/libnss.hash
package/libnss/libnss.mk

index 916aade5b1adb712158d9703343760d1c4f0bd8b..5664e93d2ffa764e058ccd6a4d1155dd90d6c0e6 100644 (file)
@@ -1,2 +1,2 @@
-# From https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_17_2_RTM/src/
-sha256 134929e44e44b968a4883f4ee513a71ae45d55b486cee41ee8e26c3cc84dab8b        nss-3.17.2.tar.gz
+# From https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_17_3_RTM/src/
+sha256 f4d5e9035a2f84f25f35c283de3b0ff60d72e918748de25eaf017ed201fa21d5        nss-3.17.3.tar.gz
index 4e174f617b3a50529666d919a436c1789a7421b3..1737cd48cc06591d5a3b16c36907ea8f7419867d 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-LIBNSS_VERSION = 3.17.2
+LIBNSS_VERSION = 3.17.3
 LIBNSS_SOURCE = nss-$(LIBNSS_VERSION).tar.gz
 LIBNSS_SITE = https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_$(subst .,_,$(LIBNSS_VERSION))_RTM/src
 LIBNSS_DISTDIR = dist