nss 2:3.45-1ubuntu2.3 source package in Ubuntu

Changelog

nss (2:3.45-1ubuntu2.3) eoan-security; urgency=medium

  * SECURITY UPDATE: invalid state after HelloRetryRequest
    - debian/patches/CVE-2019-17023-1.patch: prevent negotiation of
      versions lower than 1.3 after HelloRetryRequest in
      nss/lib/ssl/ssl3con.c, nss/lib/ssl/tls13con.c.
    - debian/patches/CVE-2019-17023-2.patch: add new tests for version
      limitations after a HRR in nss/gtests/ssl_gtest/ssl_hrr_unittest.cc.
    - CVE-2019-17023
  * SECURITY UPDATE: Timing attack during DSA key generation
    - debian/patches/CVE-2020-12399.patch: force a fixed length for DSA
      exponentiation in nss/lib/freebl/dsa.c.
    - CVE-2020-12399

 -- Marc Deslauriers <email address hidden>  Wed, 10 Jun 2020 12:57:22 -0400

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Eoan
Original maintainer:
Ubuntu Developers
Architectures:
any
Section:
libs
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
nss_3.45.orig.tar.gz 72.5 MiB 112f05223d1fde902c170966bfc6f011b24a838be16969b110ecf2bb7bc24e8b
nss_3.45-1ubuntu2.3.debian.tar.xz 28.1 KiB 39c7d538ce91d3bfb9cd923307460018248bb21504da403c3501e746567cc710
nss_3.45-1ubuntu2.3.dsc 2.2 KiB 7c496f816f3c0992afa28a3be2bc6bbe7be870e4d7ab4117668dc6dbf9cb1553

View changes file

Binary packages built by this source

libnss3: No summary available for libnss3 in ubuntu eoan.

No description available for libnss3 in ubuntu eoan.

libnss3-dbgsym: No summary available for libnss3-dbgsym in ubuntu eoan.

No description available for libnss3-dbgsym in ubuntu eoan.

libnss3-dev: No summary available for libnss3-dev in ubuntu eoan.

No description available for libnss3-dev in ubuntu eoan.

libnss3-tools: No summary available for libnss3-tools in ubuntu eoan.

No description available for libnss3-tools in ubuntu eoan.

libnss3-tools-dbgsym: No summary available for libnss3-tools-dbgsym in ubuntu eoan.

No description available for libnss3-tools-dbgsym in ubuntu eoan.