nss: security bump to version 3.23
authorGustavo Zacarias <gustavo@zacarias.com.ar>
Wed, 30 Mar 2016 19:51:07 +0000 (16:51 -0300)
committerThomas Petazzoni <thomas.petazzoni@free-electrons.com>
Thu, 31 Mar 2016 01:43:58 +0000 (03:43 +0200)
Fixes:
CVE-2016-1950 - Fixed a heap-based buffer overflow related to the
parsing of certain ASN.1 structures. An attacker could create a
specially-crafted certificate which, when parsed by NSS, would cause a
crash or execution of arbitrary code with the permissions of the user.

Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@free-electrons.com>
package/libnss/libnss.hash
package/libnss/libnss.mk

index 143e1d872aeb5189cdfe96c296c995e74d8fa9dc..8e03faf31c20a8bd254f26ea6b4c1f1496a785eb 100644 (file)
@@ -1,2 +1,2 @@
-# From https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_22_2_RTM/src/SHA256SUMS
-sha256 07d49287c527ac31200f02dcf8494cef19e936d8ed470802749c4dfc782d3650        nss-3.22.2.tar.gz
+# From https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_23_RTM/src/SHA256SUMS
+sha256 94b383e31c9671e9dfcca81084a8a813817e8f05a57f54533509b318d26e11cf        nss-3.23.tar.gz
index 18dc62cb061b52e59aa4297217b55363b2d858f5..e2bbf1f39fed4f0252aabcb7ed767a80c67e91d3 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-LIBNSS_VERSION = 3.22.2
+LIBNSS_VERSION = 3.23
 LIBNSS_SOURCE = nss-$(LIBNSS_VERSION).tar.gz
 LIBNSS_SITE = https://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_$(subst .,_,$(LIBNSS_VERSION))_RTM/src
 LIBNSS_DISTDIR = dist