diff options
author | Gustavo Zacarias <gustavo@zacarias.com.ar> | 2014-12-16 08:12:54 -0300 |
---|---|---|
committer | Peter Korsgaard <peter@korsgaard.com> | 2014-12-16 23:48:32 +0100 |
commit | 6efc256a7762ed388ca57d809ceb3fc9f6776b7d (patch) | |
tree | f474acf90dac943ee9d57f5fe731595d2c1cdda4 /package/php/php.hash | |
parent | 267899db398439b9068c3e13c20209171d5936a1 (diff) |
libnss: security bump to version 3.17.3
Fixes CVE-2014-1569 - The definite_length_decoder function in
lib/util/quickder.c in Mozilla Network Security Services (NSS) before
3.16.2.4 and 3.17.x before 3.17.3 does not ensure that the DER encoding
of an ASN.1 length is properly formed, which allows remote attackers to
conduct data-smuggling attacks by using a long byte sequence for an
encoding.
Signed-off-by: Gustavo Zacarias <gustavo@zacarias.com.ar>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Diffstat (limited to 'package/php/php.hash')
0 files changed, 0 insertions, 0 deletions