FS#42760 - [nss] CVE-2014-1569: ASN.1 DER decoding of lengths is too permissive
Attached to Project:
Arch Linux
Opened by Remi Gacogne (rgacogne) - Wednesday, 12 November 2014, 11:04 GMT
Last edited by Evangelos Foutras (foutrelis) - Tuesday, 16 December 2014, 10:58 GMT
Opened by Remi Gacogne (rgacogne) - Wednesday, 12 November 2014, 11:04 GMT
Last edited by Evangelos Foutras (foutrelis) - Tuesday, 16 December 2014, 10:58 GMT
|
Details
Summary:
A security issue has been found[0] in NSS, allowing an attacker to smuggle undetected arbitrary data into an ASN.1 object. This issue has been assigned CVE-2014-1569. Mitigation: The problem has been fixed upstream [1] but there has not been a new release yet. I think we should consider backporting the patch until a release is available. [0]: https://bugzilla.mozilla.org/show_bug.cgi?id=1064670 [1]: https://hg.mozilla.org/projects/nss/rev/e9a7991380db |
This task depends upon
Closed by Evangelos Foutras (foutrelis)
Tuesday, 16 December 2014, 10:58 GMT
Reason for closing: Fixed
Additional comments about closing: nss 3.17.3-2
Tuesday, 16 December 2014, 10:58 GMT
Reason for closing: Fixed
Additional comments about closing: nss 3.17.3-2
Comment by Remi Gacogne (rgacogne) -
Monday, 01 December 2014, 15:58 GMT
Comment by
Levente Polyak (anthraxx) -
Tuesday, 16 December 2014, 10:49 GMT
NSS 3.17.3 has been released:
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.17.3_release_notes
nss 3.17.3-2 already in the repos, this ticket can be closed